|
198211
|
5.9 |
MEDIUM
Network
|
siemens
|
logo\!_soft_comfort
|
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to mani…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-12740
|
2024-11-21 12:10 |
2017-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198212
|
8.8 |
HIGH
Adjacent
|
siemens
|
scalance_xb-200_firmware scalance_xc-200_firmware scalance_xp-200_firmware scalance_xr300-wg_firmware scalance_xr-500_firmware scalance_xm-400_firmware ruggedcom_ros
|
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR3…
|
CWE-665
Improper Initialization
|
CVE-2017-12736
|
2024-11-21 12:10 |
2017-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198213
|
5.9 |
MEDIUM
Network
|
wolfssl siemens arubanetworks
|
wolfssl scalance_w1750d_firmware instant
|
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable wolfSSL…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-13099
|
2024-11-21 12:10 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198214
|
5.9 |
MEDIUM
Network
|
bouncycastle
|
legion-of-the-bouncy-castle-java-crytography-api
|
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite usin…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-13098
|
2024-11-21 12:10 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198215
|
7.8 |
HIGH
Local
|
qnap
|
qsync
|
A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.
|
CWE-426
Untrusted Search Path
|
CVE-2017-13070
|
2024-11-21 12:10 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198216
|
7.8 |
HIGH
Local
|
kaspersky
|
embedded_systems_security
|
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12823
|
2024-11-21 12:10 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198217
|
9.8 |
CRITICAL
Network
|
qnap
|
video_station
|
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earli…
|
CWE-77
Command Injection
|
CVE-2017-13071
|
2024-11-21 12:10 |
2017-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198218
|
9.8 |
CRITICAL
Network
|
siemens
|
sm-2556_firmware
|
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected …
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2017-12739
|
2024-11-21 12:10 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198219
|
6.1 |
MEDIUM
Network
|
siemens
|
sm-2556_firmware
|
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected …
|
CWE-79
Cross-site Scripting
|
CVE-2017-12738
|
2024-11-21 12:10 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198220
|
5.3 |
MEDIUM
Network
|
siemens
|
sm-2556_firmware
|
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected …
|
CWE-200
Information Exposure
|
CVE-2017-12737
|
2024-11-21 12:10 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|