Show filters
346 Total Results
Displaying 1-10 of 346
Sort by:
Attacker Value
Unknown
CVE-2024-8401
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an authenticated attacker modifies folder names within the context of
the product.
0
Attacker Value
Unknown
CVE-2024-12703
Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity
and potential remote code execution on workstation when a non-admin authenticated user opens a malicious
project file.
0
Attacker Value
Unknown
CVE-2024-10313
Disclosure Date: October 24, 2024 (last updated October 25, 2024)
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal
vulnerability. When the software loads a malicious ‘ems' project
template file constructed by an attacker, it can write files to
arbitrary directories. This can lead to overwriting system files,
causing system paralysis, or writing to startup items, resulting in
remote control.
0
Attacker Value
Unknown
CVE-2024-9414
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
0
Attacker Value
Unknown
CVE-2024-47221
Disclosure Date: September 22, 2024 (last updated September 29, 2024)
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
0
Attacker Value
Unknown
CVE-2024-8232
Disclosure Date: September 10, 2024 (last updated September 11, 2024)
SpiderControl SCADA Web Server has a vulnerability that could allow an
attacker to upload specially crafted malicious files without
authentication.
0
Attacker Value
Unknown
CVE-2024-7941
Disclosure Date: August 27, 2024 (last updated October 31, 2024)
An HTTP parameter may contain a URL value and could cause
the web application to redirect the request to the specified URL.
By modifying the URL value to a malicious site, an attacker may
successfully launch a phishing scam and steal user credentials.
0
Attacker Value
Unknown
CVE-2024-7940
Disclosure Date: August 27, 2024 (last updated August 29, 2024)
The product exposes a service that is intended for local only to
all network interfaces without any authentication.
0
Attacker Value
Unknown
CVE-2024-4872
Disclosure Date: August 27, 2024 (last updated October 31, 2024)
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability
an attacker must have a valid credential.
0
Attacker Value
Unknown
CVE-2024-3982
Disclosure Date: August 27, 2024 (last updated August 29, 2024)
An attacker with local access to machine where MicroSCADA X
SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level
is not enabled and only users with administrator rights can enable it.
0