Show filters
222 Total Results
Displaying 71-80 of 222
Sort by:
Attacker Value
Unknown

CVE-2022-38743

Disclosure Date: October 17, 2022 (last updated February 24, 2025)
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.
Attacker Value
Unknown

CVE-2022-39212

Disclosure Date: September 17, 2022 (last updated February 24, 2025)
Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to upgrade should select "None" as camera before joining the call.
Attacker Value
Unknown

CVE-2022-35932

Disclosure Date: August 12, 2022 (last updated February 24, 2025)
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.
Attacker Value
Unknown

CVE-2022-24890

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2022-24887

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs. This issue is fixed in versions 11.3.4, 12.2.2, and 13.0.0. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2021-32960

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.
Attacker Value
Unknown

CVE-2022-22995

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Attacker Value
Unknown

CVE-2021-27476

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
Attacker Value
Unknown

CVE-2021-27474

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27472

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.