|
196271
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notif…
|
CWE-89
SQL Injection
|
CVE-2020-7500
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196272
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
mtn6501-0001_firmware mtn6501-0002_firmware mtn6260-0410_firmware mtn6260-0415_firmware mtn6260-0310_firmware mtn6260-0315_firmware
|
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low p…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7499
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196273
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
os_loader unity_loader
|
A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fix…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7498
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196274
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
ecostruxure_operator_terminal_expert
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as V…
|
CWE-22
Path Traversal
|
CVE-2020-7497
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196275
|
7.8 |
HIGH
Local
|
se
|
ecostruxure_operator_terminal_expert
|
A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write…
|
CWE-88
Argument Injection
|
CVE-2020-7496
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196276
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
ecostruxure_operator_terminal_expert
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and…
|
CWE-22
Path Traversal
|
CVE-2020-7495
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196277
|
7.8 |
HIGH
Local
|
schneider-electric
|
ecostruxure_operator_terminal_expert
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as V…
|
CWE-22
Path Traversal
|
CVE-2020-7494
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196278
|
7.8 |
HIGH
Local
|
schneider-electric
|
ecostruxure_operator_terminal_expert
|
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly know…
|
CWE-89
SQL Injection
|
CVE-2020-7493
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196279
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
gp-pro_ex_firmware
|
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not…
|
CWE-521
Weak Password Requirements
|
CVE-2020-7492
|
2024-11-21 14:37 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196280
|
9.1 |
CRITICAL
Network
|
siemens
|
logo\!_8_bm_firmware
|
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project…
|
-
|
CVE-2020-7589
|
2024-11-21 14:37 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|