|
222971
|
7.5 |
HIGH
Network
|
siemens
|
scalance_xc-200_firmware scalance_xf-200_firmware scalance_xp-200_firmware scalance_xb-200_firmware scalance_x-200irt_firmware scalance_x-200irt_pro_firmware scalance_xr-300wg_firmw…
|
A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X202-2IRT, SCALANCE X202-2P IRT, SCALANCE X202-2P IRT PRO, SCALANCE X204-2, SCALA…
|
-
|
CVE-2019-19301
|
2024-11-21 13:34 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222972
|
7.5 |
HIGH
Network
|
siemens
|
ktk_ate530s_firmware sidoor_atd430w_firmware sidoor_ate530s_coated_firmware sidoor_ate531s_firmware simatic_et_200sp_open_controller_cpu_1515sp_pc_firmware simatic_et_200sp_open_contro…
|
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE53…
|
-
|
CVE-2019-19300
|
2024-11-21 13:34 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222973
|
7.0 |
HIGH
Local
|
redhat
|
openshift
|
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacke…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19348
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222974
|
7.0 |
HIGH
Local
|
redhat
|
openshift
|
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An att…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19346
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222975
|
7.5 |
HIGH
Network
|
hitachienergy
|
esoms
|
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connectio…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-19097
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222976
|
6.1 |
MEDIUM
Local
|
hitachienergy
|
esoms
|
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' co…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19096
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222977
|
5.4 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19095
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222978
|
7.6 |
HIGH
Network
|
hitachienergy
|
esoms
|
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
|
CWE-89
SQL Injection
|
CVE-2019-19094
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222979
|
6.5 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
|
CWE-521
Weak Password Requirements
|
CVE-2019-19093
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222980
|
3.5 |
LOW
Network
|
hitachienergy
|
esoms
|
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19092
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|