|
195211
|
7.5 |
HIGH
Network
|
schneider-electric
|
scadapack_312e_firmware scadapack_313e_firmware scadapack_314e_firmware scadapack_330e_firmware scadapack_333e_firmware scadapack_334e_firmware scadapack_337e_firmware scadapack_…
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RT…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-22816
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195212
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including S…
|
CWE-200
Information Exposure
|
CVE-2021-22815
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195213
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and dis…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22814
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195214
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22725
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195215
|
8.8 |
HIGH
Network
|
schneider-electric
|
evc1s22p4_firmware evc1s7p4_firmware evw2_firmware evf2_firmware evp2pe_firmware evb1a_firmware
|
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submit…
|
CWE-352
Origin Validation Error
|
CVE-2021-22724
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195216
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22813
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195217
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22812
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195218
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution when the request of a privileged account accessin…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22811
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195219
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
network_management_card_2_firmware network_management_card_3_firmware
|
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22810
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195220
|
7.0 |
HIGH
Local
|
linux debian netapp
|
linux_kernel debian_linux h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware
|
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past t…
|
CWE-415
Double Free
|
CVE-2021-22600
|
2024-11-21 14:50 |
2022-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|