|
197251
|
7.2 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to inject data with dangerous content into the…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7505
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197252
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially…
|
CWE-20
Improper Input Validation
|
CVE-2020-7504
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197253
|
8.8 |
HIGH
Network
|
schneider-electric
|
easergy_t300_firmware
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitim…
|
CWE-352
Origin Validation Error
|
CVE-2020-7503
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197254
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m218_firmware
|
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sen…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7502
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197255
|
8.8 |
HIGH
Network
|
schneider-electric
|
vijeo_designer
|
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7501
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197256
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notif…
|
CWE-89
SQL Injection
|
CVE-2020-7500
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197257
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low p…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7499
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197258
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
os_loader unity_loader
|
A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fix…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7498
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197259
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
ecostruxure_operator_terminal_expert
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as V…
|
CWE-22
Path Traversal
|
CVE-2020-7497
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197260
|
7.8 |
HIGH
Local
|
se
|
ecostruxure_operator_terminal_expert
|
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write…
|
CWE-88
Argument Injection
|
CVE-2020-7496
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|