Show filters
820 Total Results
Displaying 51-60 of 820
Sort by:
Attacker Value
Unknown

CVE-2024-7940

Disclosure Date: August 27, 2024 (last updated August 29, 2024)
The product exposes a service that is intended for local only to all network interfaces without any authentication.
Attacker Value
Unknown

CVE-2024-4872

Disclosure Date: August 27, 2024 (last updated October 31, 2024)
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
Attacker Value
Unknown

CVE-2024-3982

Disclosure Date: August 27, 2024 (last updated August 29, 2024)
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
Attacker Value
Unknown

CVE-2024-3980

Disclosure Date: August 27, 2024 (last updated October 31, 2024)
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
Attacker Value
Unknown

CVE-2024-8105

Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown

CVE-2024-44076

Disclosure Date: August 19, 2024 (last updated August 22, 2024)
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
Attacker Value
Unknown

CVE-2024-7567

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
0
Attacker Value
Unknown

CVE-2024-40101

Disclosure Date: August 06, 2024 (last updated August 30, 2024)
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter.
Attacker Value
Unknown

CVE-2023-28074

Disclosure Date: July 31, 2024 (last updated August 20, 2024)
Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Attacker Value
Unknown

CVE-2024-38734

Disclosure Date: July 12, 2024 (last updated July 13, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
0