|
194371
|
8.6 |
HIGH
Local
|
rockwellautomation
|
connected_components_workbench
|
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automatio…
|
CWE-22
Path Traversal
|
CVE-2021-27471
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194372
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated at…
|
CWE-89
SQL Injection
|
CVE-2021-27468
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194373
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27466
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194374
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticate…
|
CWE-89
SQL Injection
|
CVE-2021-27464
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194375
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a rem…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27462
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194376
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_assetcentre
|
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will b…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2021-27460
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194377
|
2.4 |
LOW
Physics
|
phillips
|
gemini_882300_firmware gemini_882160_firmware gemini_882400_firmware gemini_882390_firmware gemini_882410_firmware gemini_882412_firmware gemini_882473_firmware gemini_882470_fir…
|
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-27456
|
2024-11-21 14:58 |
2022-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194378
|
6.5 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements that expose sensitive information to the program's standard output device. An …
|
NVD-CWE-Other
|
CVE-2021-27789
|
2024-11-21 14:58 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194379
|
7.5 |
HIGH
Network
|
hcltech
|
bigfix_compliance
|
"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it."
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-27756
|
2024-11-21 14:58 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194380
|
7.5 |
HIGH
Network
|
hcltech
|
bigfix_insights
|
" Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.Since the information is stored in cle…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-27757
|
2024-11-21 14:58 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|