Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2024-25138
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
In AutomationDirect C-MORE EA9 HMI,
credentials used by the platform are stored as plain text on the device.
0
Attacker Value
Unknown
CVE-2024-25137
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can lead to denial-of-service conditions.
0
Attacker Value
Unknown
CVE-2024-25136
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
0