|
210421
|
7.5 |
HIGH
Network
|
osisoft
|
pi_data_archive
|
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connecti…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-10604
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210422
|
7.8 |
HIGH
Local
|
osisoft
|
pi_buffer_subsystem pi_api pi_connector pi_connector_relay pi_interface_configuration_utility pi_integrator pi_data_collection_manager pi_data_archive pi_to_ocs
|
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at W…
|
CWE-426
Untrusted Search Path
|
CVE-2020-10610
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210423
|
7.8 |
HIGH
Local
|
osisoft
|
pi_buffer_subsystem pi_api pi_connector pi_connector_relay pi_interface_configuration_utility pi_integrator pi_data_collection_manager pi_data_archive pi_to_ocs
|
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-10608
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210424
|
5.3 |
MEDIUM
Network
|
pi
|
data_archive
|
In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due to a race condition. This can result in blocking connections and queries to PI…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10602
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210425
|
7.1 |
HIGH
Network
|
osisoft
|
pi_data_archive
|
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10600
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210426
|
7.8 |
HIGH
Local
|
osisoft
|
pi_buffer_subsystem pi_api pi_connector pi_connector_relay pi_interface_configuration_utility pi_integrator pi_data_collection_manager pi_data_archive pi_to_ocs
|
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information di…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-10606
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210427
|
7.5 |
HIGH
Network
|
grundfos
|
cim_500_firmware
|
Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10605
|
2024-11-21 13:55 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210428
|
9.8 |
CRITICAL
Network
|
abb
|
robotware
|
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't em…
|
CWE-287
Improper Authentication
|
CVE-2020-10288
|
2024-11-21 13:55 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210429
|
8.8 |
HIGH
Adjacent
|
ufactory
|
xarm_5_lite_firmware xarm_6_firmware xarm_7_firmware
|
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible fil…
|
CWE-269
Improper Privilege Management
|
CVE-2020-10286
|
2024-11-21 13:55 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210430
|
9.8 |
CRITICAL
Network
|
ufactory
|
xarm_5_lite_firmware
|
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts t…
|
CWE-331
Insufficient Entropy
|
CVE-2020-10285
|
2024-11-21 13:55 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|