|
222931
|
8.8 |
HIGH
Network
|
siemens
|
sinvr_3_video_server sinvr_3_central_control_server
|
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an SQL injection
vulnerability in its XML-based communication prot…
|
-
|
CVE-2019-19292
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222932
|
7.5 |
HIGH
Network
|
siemens
|
simatic_pcs_7 simatic_wincc simatic_batch simatic_route_control simatic_net_pc openpcs_7
|
A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (…
|
-
|
CVE-2019-19282
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222933
|
7.5 |
HIGH
Network
|
siemens
|
simatic_et_200sp_open_controller_cpu_1515sp_pc2_firmware simatic_s7-1500_cpu_1511-1_pn_firmware simatic_s7-1500_cpu_1513-1_pn_firmware simatic_s7-1500_cpu_1515-2_pn_firmware simatic_s7-15…
|
A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < V20.8), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-19281
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222934
|
6.5 |
MEDIUM
Network
|
siemens
|
siport_mp
|
A vulnerability has been identified in SIPORT MP (All versions < 3.1.4). Vulnerable versions of the device allow the creation of special accounts ("service users") with administrative privileges that…
|
NVD-CWE-Other
|
CVE-2019-19277
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222935
|
7.5 |
HIGH
Network
|
siemens
|
siprotec_4 siprotec_compact
|
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of th…
|
CWE-20
Improper Input Validation
|
CVE-2019-19279
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222936
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2680_firmware
|
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable MAC address filtering by submitting a crafted Form…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19226
|
2024-11-21 13:34 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222937
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2680_firmware
|
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers without being authenticated on the admin interfac…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19225
|
2024-11-21 13:34 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222938
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2680_firmware
|
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the configuration (binary file) settings by submitting a ro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19224
|
2024-11-21 13:34 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222939
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2680_firmware
|
A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router by submitting a reboot.html GET request without be…
|
CWE-79 CWE-444
Cross-site Scripting HTTP Request Smuggling
|
CVE-2019-19223
|
2024-11-21 13:34 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222940
|
5.4 |
MEDIUM
Network
|
dlink
|
dsl-2680_firmware
|
A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page b…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19222
|
2024-11-21 13:34 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|