Latest CVE Feed
-
7.8
HIGHCVE-2021-33737
A vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 ERPC (All versions), SIMATIC CP 343-1 Lean (incl. SIPLUS variants) (All vers... Read more
Affected Products : simatic_cp_443-1_firmware simatic_cp_443-1_advanced_firmware siplus_net_cp_443-1_firmware siplus_net_cp_443-1_advanced_firmware simatic_cp_343-1_firmware simatic_cp_343-1_advanced_firmware simatic_cp_343-1_erpc_firmware simatic_cp_343-1_lean_firmware simatic_cp_443-1 simatic_cp_443-1_advanced +4 more products- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33736
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33735
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33734
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33733
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33732
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33731
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-33730
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33729
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is able to import firmware containers to an affected system could execute arbitrary commands in the local database.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-33728
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to upload JSON objects that are deserialized to JAVA objects. Due to insecure deserialization of user-supplied content by the affected software... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-33727
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any user. With this, the attacker could leak confidential information of any user in the affected system.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33726
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to download arbitrary files under a user controlled path and does not correctly check if the relative path is still within the intended target ... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-33725
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the int... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-33724
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path.... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-33723
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change the password of any user in the aff... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-33722
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability when exporting a firmware container. With this a privileged authenticated attacker could create arbitrary files on ... Read more
Affected Products : sinec_nms- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-33721
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with admin... Read more
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33720
A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted ... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33719
A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted ... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-33718
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.22), Mendix Applications using Mendix 8 (All versions < V8.18.7), Mendix Applications using Mendix 9 (All versions < V9.3.0). Write access checks of attributes... Read more
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024