|
195191
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m218_firmware
|
A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M21…
|
-
|
CVE-2021-22800
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195192
|
7.5 |
HIGH
Network
|
schneider-electric
|
conext_combox_firmware
|
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext? ComBo…
|
-
|
CVE-2021-22798
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195193
|
7.8 |
HIGH
Local
|
schneider-electric
|
c-gate_server
|
A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V…
|
-
|
CVE-2021-22796
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195194
|
8.8 |
HIGH
Network
|
schneider-electric
|
c-bus_toolkit
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus To…
|
-
|
CVE-2021-22748
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195195
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoc0401_firmware bmxnor0200h_rtu_firmware tsxp574634_firmware tsxp575634_firmware tsxp576634_firmware<…
|
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modic…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22788
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195196
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoc0401_firmware bmxnor0200h_rtu_firmware tsxp574634_firmware tsxp575634_firmware tsxp576634_firmware<…
|
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affe…
|
CWE-20
Improper Input Validation
|
CVE-2021-22787
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195197
|
7.5 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoc0401_firmware bmxnor0200h_rtu_firmware tsxp574634_firmware tsxp575634_firmware tsxp576634_firmware<…
|
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server …
|
CWE-200
Information Exposure
|
CVE-2021-22785
|
2024-11-21 14:50 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195198
|
7.8 |
HIGH
Local
|
schneider-electric
|
hmibmuhi29d2801_firmware hmibmusi29d2801_firmware hmibmuci29d2w01_firmware hmibmu0i29d2001_firmware hmibmu0i29d200a_firmware hmibmuhi29d4801_firmware hmibmusi29d4801_firmware hmi…
|
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/…
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-22817
|
2024-11-21 14:50 |
2022-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195199
|
8.8 |
HIGH
Network
|
schneider-electric
|
ecostruxure_power_monitoring_expert
|
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826.…
|
CWE-20
Improper Input Validation
|
CVE-2021-22827
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195200
|
8.8 |
HIGH
Network
|
schneider-electric
|
ecostruxure_power_monitoring_expert
|
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827.…
|
CWE-20
Improper Input Validation
|
CVE-2021-22826
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|