Show filters
796 Total Results
Displaying 81-90 of 796
Sort by:
Attacker Value
Unknown

CVE-2023-37197

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration settings of endpoints on DCE.
Attacker Value
Unknown

CVE-2023-37196

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
Attacker Value
Unknown

CVE-2023-3001

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
Attacker Value
Unknown

CVE-2023-2570

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
Attacker Value
Unknown

CVE-2023-2569

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Attacker Value
Unknown

CVE-2023-1049

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Attacker Value
Unknown

CVE-2022-46680

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
Attacker Value
Unknown

CVE-2023-2161

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user. 
Attacker Value
Unknown

CVE-2023-25620

Disclosure Date: April 19, 2023 (last updated October 08, 2023)
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
Attacker Value
Unknown

CVE-2023-25619

Disclosure Date: April 19, 2023 (last updated October 08, 2023)
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.