Show filters
129 Total Results
Displaying 41-50 of 129
Sort by:
Attacker Value
Unknown

CVE-2021-45917

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer within the local area network can use the local registry information to launch server-side request forgery (SSRF) attack on another agent computer, resulting in arbitrary code execution for controlling the system or disrupting service.
Attacker Value
Unknown

CVE-2021-45099

Disclosure Date: December 16, 2021 (last updated November 08, 2023)
The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a defense-in-depth measure against complex social engineering situations
Attacker Value
Unknown

CVE-2021-27188

Disclosure Date: February 12, 2021 (last updated February 22, 2025)
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.
Attacker Value
Unknown

CVE-2021-27187

Disclosure Date: February 12, 2021 (last updated February 22, 2025)
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.
Attacker Value
Unknown

CVE-2020-28221

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
Attacker Value
Unknown

CVE-2020-35338

Disclosure Date: December 14, 2020 (last updated February 22, 2025)
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
Attacker Value
Unknown

CVE-2020-23727

Disclosure Date: December 03, 2020 (last updated November 28, 2024)
There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD).
Attacker Value
Unknown

CVE-2020-7544

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
Attacker Value
Unknown

CVE-2020-14930

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.
Attacker Value
Unknown

CVE-2020-7495

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when opening the project file.