|
210341
|
6.3 |
MEDIUM
Local
|
bbraun
|
datamodule_compactplus spacecom
|
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devic…
|
NVD-CWE-Other
|
CVE-2020-25160
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210342
|
6.1 |
MEDIUM
Network
|
bbraun
|
datamodule_compactplus spacecom
|
A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to…
|
-
|
CVE-2020-25158
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210343
|
7.2 |
HIGH
Network
|
bbraun
|
datamodule_compactplus spacecom
|
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to a…
|
-
|
CVE-2020-25156
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210344
|
6.1 |
MEDIUM
Network
|
bbraun
|
datamodule_compactplus spacecom
|
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows at…
|
-
|
CVE-2020-25154
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210345
|
8.1 |
HIGH
Network
|
bbraun
|
datamodule_compactplus spacecom
|
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attacke…
|
-
|
CVE-2020-25152
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210346
|
8.8 |
HIGH
Network
|
bbraun
|
datamodule_compactplus spacecom
|
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges …
|
CWE-22
Path Traversal
|
CVE-2020-25150
|
2024-11-21 14:17 |
2022-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210347
|
8.8 |
HIGH
Network
|
ge
|
rt430_firmware rt431_firmware rt434_firmware
|
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacke…
|
CWE-94
Code Injection
|
CVE-2020-25197
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210348
|
5.3 |
MEDIUM
Network
|
ge
|
rt430_firmware rt431_firmware rt434_firmware
|
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encry…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-25193
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210349
|
5.5 |
MEDIUM
Local
|
schneider-electric rockwellautomation xylem
|
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<…
|
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-25184
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210350
|
6.7 |
MEDIUM
Local
|
schneider-electric rockwellautomation xylem
|
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<…
|
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to e…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25182
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|