Show filters
62 Total Results
Displaying 41-50 of 62
Sort by:
Attacker Value
Unknown
CVE-2021-27660
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
0
Attacker Value
Unknown
CVE-2021-27661
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.
0
Attacker Value
Unknown
CVE-2021-27659
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
0
Attacker Value
Unknown
CVE-2021-27658
Disclosure Date: June 24, 2021 (last updated February 22, 2025)
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
0
Attacker Value
Unknown
CVE-2021-27657
Disclosure Date: June 04, 2021 (last updated February 22, 2025)
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.
0
Attacker Value
Unknown
CVE-2021-27656
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.
0
Attacker Value
Unknown
CVE-2020-9050
Disclosure Date: February 18, 2021 (last updated February 22, 2025)
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.
0
Attacker Value
Unknown
CVE-2020-9049
Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.
0
Attacker Value
Unknown
CVE-2020-9048
Disclosure Date: October 08, 2020 (last updated February 22, 2025)
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service attack.
0
Attacker Value
Unknown
CVE-2020-9047
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.
0