|
212491
|
10.0 |
CRITICAL
Network
|
adcon
|
a840_telemetry_gateway_base_station_firmware
|
Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2015-7930
|
2024-11-21 11:37 |
2015-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212492
|
4.3 |
MEDIUM
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Re…
|
CWE-200
Information Exposure
|
CVE-2015-7929
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212493
|
8.5 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workst…
|
CWE-200
Information Exposure
|
CVE-2015-7928
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212494
|
6.1 |
MEDIUM
Network
|
ewon
|
ewon_firmware
|
Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7927
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212495
|
9.9 |
CRITICAL
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.
|
CWE-200
Information Exposure
|
CVE-2015-7926
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212496
|
8.0 |
HIGH
Network
|
ewon
|
ewon_firmware
|
Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware …
|
CWE-352
Origin Validation Error
|
CVE-2015-7925
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212497
|
8.8 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveragi…
|
NVD-CWE-Other
|
CVE-2015-7924
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212498
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
|
CWE-352
Origin Validation Error
|
CVE-2015-7936
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212499
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7935
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212500
|
7.2 |
HIGH
Local
|
opcsystems
|
opc_systems.net
|
Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
|
NVD-CWE-Other
|
CVE-2015-7917
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|