Show filters
455 Total Results
Displaying 1-10 of 455
Sort by:
Attacker Value
Unknown

CVE-2024-10334

Disclosure Date: February 10, 2025 (last updated February 11, 2025)
A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  An attacker who successfully exploited the vulnerability could, in the worst case scenario, stop or manipulate the video feed. This issue affects System 800xA: 5.1.X; System 800xA: 6.0.3.X; System 800xA: 6.1.1.X; System 800xA: 6.2.X.
0
Attacker Value
Unknown

CVE-2024-51547

Disclosure Date: February 06, 2025 (last updated February 06, 2025)
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
0
Attacker Value
Unknown

CVE-2024-48852

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.
0
Attacker Value
Unknown

CVE-2024-48849

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.
0
Attacker Value
Unknown

CVE-2024-48841

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.
0
Attacker Value
Unknown

CVE-2025-23694

Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Shabbos Commerce Shabbos and Yom Tov allows Stored XSS.This issue affects Shabbos and Yom Tov: from n/a through 1.9.
0
Attacker Value
Unknown

CVE-2024-12430

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into a specifically crafted file, which then will be executed by root user. All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.
0
Attacker Value
Unknown

CVE-2024-12429

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.
0
Attacker Value
Unknown

CVE-2024-6784

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0
Attacker Value
Unknown

CVE-2024-6516

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0