Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2021-34572
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead timestamps of the sensor are replaced by the time of the readout even if the data is a replay of earlier data.
0
Attacker Value
Unknown
CVE-2021-34571
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary can learn all information that is available in Enbra EWM.
0
Attacker Value
Unknown
CVE-2021-34573
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are not reconized or misinterpreted. This may lead to wrong values and missing events.
0
Attacker Value
Unknown
CVE-2019-14362
Disclosure Date: July 28, 2019 (last updated November 27, 2024)
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
0
Attacker Value
Unknown
CVE-2017-9437
Disclosure Date: June 05, 2017 (last updated November 26, 2024)
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
0
Attacker Value
Unknown
CVE-2013-3617
Disclosure Date: November 02, 2013 (last updated October 05, 2023)
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
0