|
210261
|
8.1 |
HIGH
Network
|
rockwellautomation
|
factorytalk_view
|
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-12028
|
2024-11-21 13:59 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210262
|
4.3 |
MEDIUM
Network
|
rockwellautomation
|
factorytalk_view
|
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaiss…
|
NVD-CWE-noinfo
|
CVE-2020-12027
|
2024-11-21 13:59 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210263
|
7.8 |
HIGH
Local
|
rockwellautomation
|
factorytalk_view
|
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoi…
|
-
|
CVE-2020-12029
|
2024-11-21 13:59 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210264
|
5.4 |
MEDIUM
Network
|
apache
|
airflow
|
An issue was found in Apache Airflow versions 1.10.10 and below. It was discovered that many of the admin management screens in the new/RBAC UI handled escaping incorrectly, allowing authenticated us…
|
CWE-79
Cross-site Scripting
|
CVE-2020-11983
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210265
|
9.8 |
CRITICAL
Network
|
apache
|
airflow
|
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious pa…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11982
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210266
|
9.8 |
CRITICAL
Network
|
apache
|
airflow
|
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, res…
|
CWE-78
OS Command
|
CVE-2020-11981
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210267
|
7.5 |
HIGH
Network
|
mitsubishielectric iconics
|
mc_works32 mc_works mobilehmi facility_analytix quality_analytix smart_energy_analytix energy_analytix genesis64 hyper_historian genesis32 bizviz
|
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 ver…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12015
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210268
|
9.1 |
CRITICAL
Network
|
mitsubishielectric iconics
|
mc_works32 mc_works64 mobilehmi facility_analytix quality_analytix smart_energy_analytix energy_analytix genesis64 hyper_historian genesis32 bizviz
|
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and…
|
CWE-89
SQL Injection
|
CVE-2020-12013
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210269
|
9.8 |
CRITICAL
Network
|
mitsubishielectric iconics
|
mc_works32 mc_works mobilehmi facility_analytix quality_analytix smart_energy_analytix energy_analytix genesis64 hyper_historian genesis32 bizviz
|
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: M…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12007
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210270
|
7.5 |
HIGH
Network
|
mitsubishielectric iconics
|
mc_works32 mc_works mobilehmi facility_analytix quality_analytix smart_energy_analytix energy_analytix genesis64 hyper_historian genesis32 bizviz
|
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Ver…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12009
|
2024-11-21 13:59 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|