|
195301
|
9.1 |
CRITICAL
Network
|
schneider-electric
|
interactive_graphical_scada_system_data_collector
|
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network …
|
-
|
CVE-2021-22805
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195302
|
7.5 |
HIGH
Network
|
schneider-electric
|
interactive_graphical_scada_system_data_collector
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to mi…
|
-
|
CVE-2021-22804
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195303
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
interactive_graphical_scada_system_data_collector
|
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders…
|
-
|
CVE-2021-22803
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195304
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
interactive_graphical_scada_system_data_collector
|
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is …
|
-
|
CVE-2021-22802
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195305
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
connexium_network_manager
|
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: C…
|
-
|
CVE-2021-22801
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195306
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m218_firmware
|
A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M21…
|
-
|
CVE-2021-22800
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195307
|
7.5 |
HIGH
Network
|
schneider-electric
|
conext_combox_firmware
|
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext? ComBo…
|
-
|
CVE-2021-22798
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195308
|
7.8 |
HIGH
Local
|
schneider-electric
|
c-gate_server
|
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V…
|
-
|
CVE-2021-22796
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195309
|
8.8 |
HIGH
Network
|
schneider-electric
|
c-bus_toolkit
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus To…
|
-
|
CVE-2021-22748
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195310
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoc0401_firmware bmxnor0200h_rtu_firmware tsxp574634_firmware tsxp575634_firmware tsxp576634_firmware<…
|
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modic…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22788
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|