|
196681
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute …
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-7508
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196682
|
7.5 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to login multiple times resulting in a denial of ser…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7507
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196683
|
7.5 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the archive with the firmware for the controller and m…
|
-
|
CVE-2020-7506
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196684
|
7.2 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to inject data with dangerous content into the…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7505
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196685
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially…
|
CWE-20
Improper Input Validation
|
CVE-2020-7504
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196686
|
8.8 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitim…
|
CWE-352
Origin Validation Error
|
CVE-2020-7503
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196687
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m218_firmware
|
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sen…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7502
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196688
|
8.8 |
HIGH
Network
|
schneider-electric
|
vijeo_designer
|
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7501
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196689
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notif…
|
CWE-89
SQL Injection
|
CVE-2020-7500
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196690
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low p…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7499
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|