|
196751
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
somachine somachine_motion ecostruxure_machine_expert modicon_m218_firmware modicon_m241_firmware modicon_m251_firmware modicon_m258_firmware
|
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-7487
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196752
|
5.4 |
MEDIUM
Network
|
lazysizes_project
|
lazysizes
|
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams wh…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7642
|
2024-11-21 14:37 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196753
|
7.5 |
HIGH
Network
|
schneider-electric
|
tricon_tcm_4351_firmware tricon_tcm_4352_firmware tricon_tcm_4351a_firmware tricon_tcm_4351b_firmware tricon_tcm_4352a_firmware tricon_tcm_4352b_firmware
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remed…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7486
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196754
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed i…
|
NVD-CWE-noinfo
|
CVE-2020-7485
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196755
|
7.5 |
HIGH
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedi…
|
NVD-CWE-noinfo
|
CVE-2020-7484
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196756
|
7.5 |
HIGH
Network
|
schneider-electric
|
tristation_1131
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediat…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7483
|
2024-11-21 14:37 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196757
|
5.3 |
MEDIUM
Network
|
s3india
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to ins…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-7802
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196758
|
5.3 |
MEDIUM
Network
|
mysyngeryss
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. The affected…
|
CWE-200
Information Exposure
|
CVE-2020-7801
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196759
|
8.2 |
HIGH
Network
|
mysyngeryss
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability. The affected produ…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-7800
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196760
|
6.1 |
MEDIUM
Network
|
siemens
|
climatix_pol908_firmware climatix_pol909_firmware
|
A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (All versions < V11.32). A persistent cross-site scripting (XSS) vulnerability e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7575
|
2024-11-21 14:37 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|