Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-31203

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
Attacker Value
Unknown

CVE-2024-31202

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
Attacker Value
Unknown

CVE-2024-31201

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
Attacker Value
Unknown

CVE-2022-30276

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.
Attacker Value
Unknown

CVE-2020-7672

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.
Attacker Value
Unknown

CVE-2018-11615

Disclosure Date: August 30, 2018 (last updated November 27, 2024)
This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of topics. A crafted regular expression can cause the broker to crash. An attacker can leverage this vulnerability to deny access to the target system. Was ZDI-CAN-6306.
0
Attacker Value
Unknown

CVE-2017-3221

Disclosure Date: July 22, 2017 (last updated November 26, 2024)
Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords.
0
Attacker Value
Unknown

CVE-2017-3222

Disclosure Date: July 22, 2017 (last updated November 26, 2024)
Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host platform with SYSTEM privileges by abusing AmosConnect Task Manager.
Attacker Value
Unknown

CVE-2015-7936

Disclosure Date: December 23, 2015 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
0
Attacker Value
Unknown

CVE-2015-7935

Disclosure Date: December 23, 2015 (last updated November 25, 2024)
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
0