|
197821
|
7.8 |
HIGH
Local
|
schneider-electric
|
guicon
|
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22807
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197822
|
3.8 |
LOW
Local
|
schneider-electric
|
software_update
|
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password…
|
CWE-331
Insufficient Entropy
|
CVE-2021-22799
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197823
|
7.5 |
HIGH
Network
|
schneider-electric
|
evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_evp2pe_firmware evlink_smart_wallbox_evb1a_firmware
|
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to the charging station web interface by performing b…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2021-22818
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197824
|
7.5 |
HIGH
Network
|
schneider-electric
|
scadapack_312e_firmware scadapack_313e_firmware scadapack_314e_firmware scadapack_330e_firmware scadapack_333e_firmware scadapack_334e_firmware scadapack_337e_firmware scadapack_…
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RT…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-22816
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197825
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including S…
|
CWE-200
Information Exposure
|
CVE-2021-22815
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197826
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and dis…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22814
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197827
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22725
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197828
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22724
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197829
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22813
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197830
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22812
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|