Show filters
796 Total Results
Displaying 61-70 of 796
Sort by:
Attacker Value
Unknown

CVE-2023-6409

Disclosure Date: February 14, 2024 (last updated December 21, 2024)
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
Attacker Value
Unknown

CVE-2023-6408

Disclosure Date: February 14, 2024 (last updated January 24, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
Attacker Value
Unknown

CVE-2023-27975

Disclosure Date: February 14, 2024 (last updated December 21, 2024)
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
Attacker Value
Unknown

CVE-2023-7032

Disclosure Date: January 09, 2024 (last updated January 17, 2024)
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
Attacker Value
Unknown

CVE-2023-6407

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
Attacker Value
Unknown

CVE-2023-5630

Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
Attacker Value
Unknown

CVE-2023-5629

Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
Attacker Value
Unknown

CVE-2023-6032

Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
Attacker Value
Unknown

CVE-2023-5987

Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
Attacker Value
Unknown

CVE-2023-5986

Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.