|
210761
|
5.3 |
MEDIUM
Network
|
inductiveautomation
|
ignition
|
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-14479
|
2024-11-21 14:03 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210762
|
5.3 |
MEDIUM
Network
|
rockwellautomation
|
1734-aentr_point_i\/o_dual_port_network_adaptor_series_b_firmware 1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware
|
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modificatio…
|
CWE-287
Improper Authentication
|
CVE-2020-14504
|
2024-11-21 14:03 |
2022-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210763
|
6.1 |
MEDIUM
Network
|
rockwellautomation
|
1734-aentr_point_i\/o_dual_port_network_adaptor_series_b_firmware 1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware
|
The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-14502
|
2024-11-21 14:03 |
2022-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210764
|
7.8 |
HIGH
Local
|
rockwellautomation
|
factorytalk_view
|
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-14481
|
2024-11-21 14:03 |
2022-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210765
|
5.5 |
MEDIUM
Local
|
rockwellautomation
|
factorytalk_view
|
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-14480
|
2024-11-21 14:03 |
2022-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210766
|
7.1 |
HIGH
Local
|
rockwellautomation
|
factorytalk_services_platform
|
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a …
|
CWE-611
XXE
|
CVE-2020-14478
|
2024-11-21 14:03 |
2022-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210767
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
cw_configurator mi_configurator gx_works3 gx_works2 melsoft_iq_appportal melsoft_navigator mr_configurator2 mt_works2 mx_component rt_toolbox3 fr_configurator2 iu_dev…
|
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-14523
|
2024-11-21 14:03 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210768
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
cw_configurator gx_logviewer melfa-works rt_toolbox2 fr_configurator_sw3 fr_configurator2 m_commdtm-io-link melsec_wincpu_setting_utility melsoft_em_software_development_kit
|
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, m…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-14521
|
2024-11-21 14:03 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210769
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14424
|
2024-11-21 14:03 |
2021-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210770
|
6.3 |
MEDIUM
Network
|
redhat
|
3scale_api_management
|
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal …
|
NVD-CWE-Other
|
CVE-2020-14388
|
2024-11-21 14:03 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|