|
221751
|
9.1 |
CRITICAL
Network
|
abb busch-jaeger
|
tg\/s3.2_firmware 6186\/11_firmware
|
Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted, such as viewing o…
|
NVD-CWE-Other
|
CVE-2019-19106
|
2024-11-21 13:34 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221752
|
5.5 |
MEDIUM
Local
|
abb busch-jaeger
|
tg\/s3.2_firmware 6186\/11_firmware
|
The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19105
|
2024-11-21 13:34 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221753
|
9.8 |
CRITICAL
Network
|
abb busch-jaeger
|
tg\/s3.2_firmware 6186\/11_firmware
|
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific unifor…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19104
|
2024-11-21 13:34 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221754
|
9.4 |
CRITICAL
Network
|
br-automation
|
automation_studio automation_runtime
|
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-19108
|
2024-11-21 13:34 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221755
|
6.1 |
MEDIUM
Network
|
northern.tech
|
cfengine
|
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19394
|
2024-11-21 13:34 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221756
|
5.4 |
MEDIUM
Network
|
matrix42
|
workspace_management
|
The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19390
|
2024-11-21 13:34 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221757
|
5.4 |
MEDIUM
Network
|
matrix42
|
workspace_management
|
Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19500
|
2024-11-21 13:34 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221758
|
7.5 |
HIGH
Network
|
siemens
|
scalance_xc-200_firmware scalance_xf-200_firmware scalance_xp-200_firmware scalance_xb-200_firmware scalance_x-200irt_firmware scalance_x-200irt_pro_firmware scalance_xr-300wg_firmw…
|
A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALA…
|
-
|
CVE-2019-19301
|
2024-11-21 13:34 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221759
|
7.5 |
HIGH
Network
|
siemens
|
ktk_ate530s_firmware sidoor_atd430w_firmware sidoor_ate530s_coated_firmware sidoor_ate531s_firmware simatic_et_200sp_open_controller_cpu_1515sp_pc_firmware simatic_et_200sp_open_contro…
|
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE53…
|
-
|
CVE-2019-19300
|
2024-11-21 13:34 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221760
|
7.0 |
HIGH
Local
|
redhat
|
openshift
|
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacke…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19348
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|