531
|
9.8 |
CRITICAL
Network
-
|
-
|
An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-1083
|
2024-10-2 15:15 |
2024-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
532
|
5.3 |
MEDIUM
Local
|
wago
|
compact_controller_100_firmware edge_controller_firmware pfc100_firmware pfc200_firmware touch_panel_600_advanced_firmware touch_panel_600_marine_firmware touch_panel_600_standard_f…
|
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privile…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2023-3379
|
2024-10-2 15:15 |
2023-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
533
|
8.8 |
HIGH
Network
|
codesys
|
development_system
|
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received…
Update
|
CWE-940
Improper Verification of Source of a Communication Channel
|
CVE-2023-3663
|
2024-10-2 15:15 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
534
|
8.8 |
HIGH
Network
|
taphome
|
core_firmware
|
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2023-2759
|
2024-10-2 15:15 |
2023-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
535
|
4.9 |
MEDIUM
Network
|
wago
|
750-331_firmware 750-8202_firmware 750-8202\/000-011_firmware 750-8202\/000-012_firmware 750-8202\/000-022_firmware 750-8202\/025-000_firmware 750-8202\/025-001_firmware 750-8202…
|
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a specifically crafted packet to the CODESYS V2 runtime.
Update
|
CWE-1288
Improper Validation of Consistency within Input
|
CVE-2023-1620
|
2024-10-2 15:15 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
536
|
4.9 |
MEDIUM
Network
|
wago
|
750-331_firmware 750-8202_firmware 750-8202\/000-011_firmware 750-8202\/000-012_firmware 750-8202\/000-022_firmware 750-8202\/025-000_firmware 750-8202\/025-001_firmware 750-8202…
|
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.
Update
|
-
|
CVE-2023-1619
|
2024-10-2 15:15 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
537
|
4.3 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
Exposure of Sensitive Information to an unauthorized actor vulnerability in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual in versions <=2.13.3 allow an authori…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2023-1779
|
2024-10-2 15:15 |
2023-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
538
|
7.5 |
HIGH
Network
wago
|
750-363\/040-000_firmware 750-362\/040-000_firmware 750-362\/000-001_firmware 750-891_firmware 750-365\/040-010_firmware 750-364\/040-010_firmware 750-362_firmware 750-363_firmwa…
|
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
Update
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2023-1150
|
2024-10-2 15:15 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
539
|
5.3 |
MEDIUM
Network
phoenixcontact
|
fl_mguard_2102_firmware fl_mguard_4102_pci_firmware fl_mguard_4102_pcie_firmware fl_mguard_4302_firmware fl_mguard_centerport_firmware fl_mguard_centerport_vpn-1000_firmware fl_mgua…
|
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the …
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2023-2673
|
2024-10-2 15:15 |
2023-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
540
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2. This…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7855
|
2024-10-2 14:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|