Show filters
796 Total Results
Displaying 61-70 of 796
Sort by:
Attacker Value
Unknown
CVE-2023-6409
Disclosure Date: February 14, 2024 (last updated December 21, 2024)
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized
access to a project file protected with application password when opening the file with
EcoStruxure Control Expert.
0
Attacker Value
Unknown
CVE-2023-6408
Disclosure Date: February 14, 2024 (last updated January 24, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of service and loss of
confidentiality, integrity of controllers when conducting a Man in the Middle attack.
0
Attacker Value
Unknown
CVE-2023-27975
Disclosure Date: February 14, 2024 (last updated December 21, 2024)
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized
access to the project file in EcoStruxure Control Expert when a local user tampers with the
memory of the engineering workstation.
0
Attacker Value
Unknown
CVE-2023-7032
Disclosure Date: January 09, 2024 (last updated January 17, 2024)
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker
logged in with a user level account to gain higher privileges by providing a harmful serialized
object.
0
Attacker Value
Unknown
CVE-2023-6407
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by
a local and low-privileged attacker.
0
Attacker Value
Unknown
CVE-2023-5630
Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a
privileged user to install an untrusted firmware.
0
Attacker Value
Unknown
CVE-2023-5629
Disclosure Date: December 14, 2023 (last updated December 28, 2023)
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could
cause disclosure of information through phishing attempts over HTTP.
0
Attacker Value
Unknown
CVE-2023-6032
Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause a file system enumeration and file download when an
attacker navigates to the Network Management Card via HTTPS.
0
Attacker Value
Unknown
CVE-2023-5987
Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to a cross site scripting condition where
attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing
the injected payload.
0
Attacker Value
Unknown
CVE-2023-5986
Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input
attackers can cause the software’s web application to redirect to the chosen domain after a
successful login is performed.
0