Latest CVE Feed
-
9.8
CRITICALCVE-2021-22795
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and ... Read more
Affected Products : struxureware_data_center_expert- EPSS Score: %3.19
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22794
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)... Read more
Affected Products : struxureware_data_center_expert- EPSS Score: %3.73
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-22793
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) that could allow an authenticated attacker to access the device via F... Read more
- EPSS Score: %0.54
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22792
A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* ... Read more
- EPSS Score: %0.46
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22791
A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and B... Read more
- EPSS Score: %0.44
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22790
A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BM... Read more
- EPSS Score: %0.44
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-22789
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file ... Read more
- EPSS Score: %0.44
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22788
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon ... Read more
- EPSS Score: %1.46
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22787
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior ... Read more
- EPSS Score: %0.43
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22786
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) ... Read more
Affected Products : modicon_m580_bmep584040_firmware modicon_m580_bmep582040_firmware modicon_m580_bmep586040_firmware modicon_m580_bmep585040_firmware modicon_m580_bmep582020_firmware modicon_m580_bmep581020_firmware modicon_m580_bmep584020_firmware modicon_m580_bmep583040_firmware modicon_m580_bmep583020_firmware modicon_m580_bmep582040s_firmware +72 more products- EPSS Score: %0.18
- Published: Feb. 01, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22785
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP... Read more
- EPSS Score: %0.32
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
5.7
MEDIUMCVE-2021-22784
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.... Read more
Affected Products : c-bus_toolkit- EPSS Score: %0.23
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22783
A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)... Read more
Affected Products : ritto_wiser_door- EPSS Score: %0.09
- Published: Mar. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22782
Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), an... Read more
- EPSS Score: %0.02
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22781
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), an... Read more
- EPSS Score: %0.05
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-22780
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), an... Read more
- EPSS Score: %0.05
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-22779
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all vers... Read more
Affected Products : modicon_m580_bmep584040_firmware modicon_m580_bmep582040_firmware modicon_m580_bmep586040_firmware modicon_m580_bmep585040_firmware modicon_m580_bmep582020_firmware modicon_m580_bmep581020_firmware modicon_m580_bmep584020_firmware modicon_m580_bmep583040_firmware modicon_m580_bmep583020_firmware ecostruxure_control_expert +51 more products- EPSS Score: %0.10
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-22778
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), an... Read more
- EPSS Score: %0.04
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22777
A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.... Read more
Affected Products : sosafe_configurable- EPSS Score: %0.36
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22775
A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.... Read more
Affected Products : gp-pro_ex- EPSS Score: %0.07
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024