|
196431
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
somachine_basic ecostruxure_machine_expert modicon_m100_firmware modicon_m200_firmware modicon_m221_firmware
|
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming …
|
CWE-74
Injection
|
CVE-2020-7489
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196432
|
7.5 |
HIGH
Network
|
schneider-electric
|
somachine somachine_motion ecostruxure_machine_expert modicon_m218_firmware modicon_m241_firmware modicon_m251_firmware modicon_m258_firmware
|
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 cont…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7488
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196433
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
somachine somachine_motion ecostruxure_machine_expert modicon_m218_firmware modicon_m241_firmware modicon_m251_firmware modicon_m258_firmware
|
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-7487
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196434
|
5.4 |
MEDIUM
Network
|
lazysizes_project
|
lazysizes
|
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams wh…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7642
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196435
|
7.5 |
HIGH
Network
|
schneider-electric
|
tricon_tcm_4351_firmware tricon_tcm_4352_firmware tricon_tcm_4351a_firmware tricon_tcm_4351b_firmware tricon_tcm_4352a_firmware tricon_tcm_4352b_firmware
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remed…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7486
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196436
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed i…
|
NVD-CWE-noinfo
|
CVE-2020-7485
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196437
|
7.5 |
HIGH
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedi…
|
NVD-CWE-noinfo
|
CVE-2020-7484
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196438
|
7.5 |
HIGH
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediat…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7483
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196439
|
5.3 |
MEDIUM
Network
|
s3india
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to ins…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7802
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196440
|
5.3 |
MEDIUM
Network
|
mysyngeryss
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. The affected…
|
CWE-200
Information Exposure
|
CVE-2020-7801
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|