| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2018-7812 | 0.0 | unknown |
No description available.
|
| CVE-2019-1181 | 0.0 | unknown |
No description available.
|
| CVE-2018-7821 | 0.0 | unknown |
No description available.
|
| CVE-2019-6843 | 0.0 | unknown |
No description available.
|
| CVE-2019-6811 | 0.0 | unknown |
No description available.
|
| CVE-2018-7809 | 0.0 | unknown |
No description available.
|
| CVE-2018-7822 | 0.0 | unknown |
No description available.
|
| CVE-2017-9627 | 0.0 | unknown |
No description available.
|
| CVE-2019-8258 | 0.0 | unknown |
CVE-2019-8258. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7773 | 0.0 | unknown |
No description available.
|
| CVE-2018-7843 | 0.0 | unknown |
CVE-2018-7843. An uncaught exception vulnerability exists which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
|
| CVE-2018-7245 | 0.0 | unknown |
No description available.
|
| CVE-2019-12260 | 0.0 | unknown |
This vulnerability could lead to a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12260 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2017-9957 | 0.0 | unknown |
No description available.
|
| CVE-2019-12261 | 0.0 | unknown |
The impact of this vulnerability is a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12261 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2014-7169 | 0.0 | unknown |
No description available.
|
| CVE-2016-2177 | 0.0 | unknown |
CVE-2016-2177. OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
|
| CVE-2018-7856 | 0.0 | unknown |
CVE-2018-7856. An uncaught exception vulnerability exists which could cause a possible denial of service when writing invalid memory blocks to the controller over Modbus.
|
| CVE-2018-7838 | 0.0 | unknown |
No description available.
|
| CVE-2017-9967 | 0.0 | unknown |
No description available.
|
| CVE-2019-11091 | 0.0 | unknown |
No description available.
|
| CVE-2019-8272 | 0.0 | unknown |
CVE-2019-8272. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6825 | 0.0 | unknown |
No description available.
|
| CVE-2019-1182 | 0.0 | unknown |
No description available.
|
| CVE-2019-6816 | 0.0 | unknown |
No description available.
|
| CVE-2015-8277 | 0.0 | unknown |
No description available.
|
| CVE-2019-8268 | 0.0 | unknown |
CVE-2019-8268. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-12257 | 0.0 | unknown |
DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN.
The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution.CVE-2019-12257 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2014-8514 | 0.0 | unknown |
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.
|
| CVE-2019-6857 | 0.0 | unknown |
This vulnerability could cause a denial-of-service condition in the controller when reading specific memory blocks using Modbus TCP.CVE-2019-6857 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2018-7846 | 0.0 | unknown |
CVE-2018-7846. A trust boundary violation vulnerability on connection to the controller exists which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
|
| CVE-2017-7494 | 0.0 | unknown |
No description available.
|
| CVE-2017-7974 | 0.0 | unknown |
No description available.
|
| CVE-2015-2291 | 0.0 | unknown |
No description available.
|
| CVE-2019-20032 | 0.0 | unknown |
No description available.
|
| CVE-2017-9969 | 0.0 | unknown |
No description available.
|
| CVE-2018-7243 | 0.0 | unknown |
No description available.
|
| CVE-2018-7789 | 0.0 | unknown |
No description available.
|
| CVE-2018-7792 | 0.0 | unknown |
No description available.
|
| CVE-2018-7759 | 0.0 | unknown |
No description available.
|
| CVE-2018-7800 | 0.0 | unknown |
No description available.
|
| CVE-2018-7849 | 0.0 | unknown |
CVE-2018-7849. An uncaught exception vulnerability exists which could cause a possible denial of service due to improper data integrity check when sending files to the controller over Modbus.
|
| CVE-2018-7802 | 0.0 | unknown |
No description available.
|
| CVE-2017-6017 | 0.0 | unknown |
No description available.
|
| CVE-2019-6838 | 0.0 | unknown |
No description available.
|
| CVE-2018-7494 | 0.0 | unknown |
No description available.
|
| CVE-2019-12259 | 0.0 | unknown |
An attacker residing on the LAN may choose to hijack a DHCP-client session that requests an IPv4 address. The attacker can send a multicast IP address in the DHCP offer/ack message, which the victim system then incorrectly assigns. This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.. CVE-2019-12264 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.
|
| CVE-2019-6830 | 0.0 | unknown |
CVE-2019-6830. An uncaught exception vulnerability exists, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
|
| CVE-2017-9629 | 0.0 | unknown |
No description available.
|
| CVE-2019-8261 | 0.0 | unknown |
CVE-2019-8261. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2017-0143 | 8.1 | high |
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 does not validate or incorrectly validates input via the SMBv1 port that can affect the control flow or data flow of a system. The SMBv1 input validation vulnerabilities could allow a remote attacker to gain unauthorized access to sensitive information, create denial of service conditions, or execute arbitrary code.For details, refer to Microsoft Security Bulletin MS17-010 and NCCIC WannaCry fact sheet.CVE-2017-0143 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2012-4681 | 0.0 | unknown |
No description available.
|
| CVE-2017-7973 | 0.0 | unknown |
No description available.
|
| CVE-2014-3566 | 0.0 | unknown |
No description available.
|
| CVE-2018-7765 | 0.0 | unknown |
No description available.
|
| CVE-2018-7770 | 0.0 | unknown |
No description available.
|
| CVE-2019-8273 | 0.0 | unknown |
CVE-2019-8273. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6808 | 0.0 | unknown |
CVE-2019-6808. An improper access control vulnerability exists, which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
|
| CVE-2017-0147 | 0.0 | unknown |
No description available.
|
| CVE-2018-7797 | 0.0 | unknown |
No description available.
|
| CVE-2018-7761 | 0.0 | unknown |
No description available.
|
| CVE-2017-9959 | 0.0 | unknown |
No description available.
|
| CVE-2019-8275 | 0.0 | unknown |
CVE-2019-8275. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-8267 | 0.0 | unknown |
CVE-2019-8267. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7794 | 0.0 | unknown |
This vulnerability could cause a denial-of-service condition when reading data with invalid index using Modbus TCP. CVE-2018-7794 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).. --------- End Update A Part 1 of 1 ---------CVE-2018-7794 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2019-20034 | 0.0 | unknown |
No description available.
|
| CVE-2019-6856 | 0.0 | unknown |
This vulnerability could cause a denial-of-service condition when writing specific physical memory blocks using Modbus TCP.CVE-2019-6856 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2018-7791 | 0.0 | unknown |
No description available.
|
| CVE-2019-12262 | 0.0 | unknown |
An attacker residing on the LAN can send reverse-ARP responses to the victim system to assign unicast IPv4 addresses to the target.CVE-2019-12262 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
|
| CVE-2018-7832 | 0.0 | unknown |
No description available.
|
| CVE-2018-7240 | 0.0 | unknown |
No description available.
|
| CVE-2019-6820 | 0.0 | unknown |
No description available.
|
| CVE-2017-9631 | 0.0 | unknown |
No description available.
|
| CVE-2019-1224 | 0.0 | unknown |
No description available.
|
| CVE-2018-7811 | 0.0 | unknown |
No description available.
|
| CVE-2019-6807 | 0.0 | unknown |
CVE-2019-6807. An uncaught exception vulnerability exists which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.
|
| CVE-2018-7763 | 0.0 | unknown |
No description available.
|
| CVE-2018-7834 | 0.0 | unknown |
No description available.
|
| CVE-2018-7852 | 0.0 | unknown |
CVE-2018-7852. An uncaught exception vulnerability exists which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
|
| CVE-2018-7772 | 0.0 | unknown |
No description available.
|
| CVE-2019-8280 | 0.0 | unknown |
CVE-2019-8280. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2016-5195 | 0.0 | unknown |
No description available.
|
| CVE-2017-3635 | 0.0 | unknown |
No description available.
|
| CVE-2019-12256 | 0.0 | unknown |
This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options.
The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution.CVE-2019-12256 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2018-7241 | 0.0 | unknown |
No description available.
|
| CVE-2017-9961 | 0.0 | unknown |
No description available.
|
| CVE-2017-7575 | 0.0 | unknown |
No description available.
|
| CVE-2018-7844 | 0.0 | unknown |
CVE-2018-7844. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
|
| CVE-2018-7803 | 0.0 | unknown |
No description available.
|
| CVE-2018-7242 | 0.0 | unknown |
No description available.
|
| CVE-2019-8269 | 0.0 | unknown |
CVE-2019-8269. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-1222 | 0.0 | unknown |
No description available.
|
| CVE-2017-7972 | 0.0 | unknown |
No description available.
|
| CVE-2019-8265 | 0.0 | unknown |
CVE-2019-8265. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6846 | 0.0 | unknown |
No description available.
|
| CVE-2017-11357 | 9.8 | critical |
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.CVE-2017-11357 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2016-10395 | 0.0 | unknown |
No description available.
|
| CVE-2018-7787 | 0.0 | unknown |
No description available.
|
| CVE-2017-6028 | 0.0 | unknown |
No description available.
|
| CVE-2018-7835 | 0.0 | unknown |
No description available.
|
| CVE-2019-6809 | 0.0 | unknown |
CVE-2019-6809. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading invalid data from the controller.
|
| CVE-2017-7574 | 0.0 | unknown |
No description available.
|
| CVE-2017-9962 | 0.0 | unknown |
No description available.
|
| CVE-2019-20033 | 0.0 | unknown |
No description available.
|
| CVE-2014-6277 | 0.0 | unknown |
No description available.
|
| CVE-2019-6812 | 0.0 | unknown |
No description available.
|
| CVE-2019-1223 | 0.0 | unknown |
No description available.
|
| CVE-2017-3652 | 0.0 | unknown |
No description available.
|
| CVE-2018-7839 | 0.0 | unknown |
No description available.
|
| CVE-2019-8263 | 0.0 | unknown |
CVE-2019-8263. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2017-3636 | 0.0 | unknown |
No description available.
|
| CVE-2018-7854 | 0.0 | unknown |
CVE-2018-7854. An uncaught exception vulnerability exists which could cause a denial of service when sending invalid debug parameters to the controller over Modbus.
|
| CVE-2019-20031 | 0.0 | unknown |
No description available.
|
| CVE-2019-6837 | 0.0 | unknown |
No description available.
|
| CVE-2018-7760 | 0.0 | unknown |
No description available.
|
| CVE-2017-5571 | 0.0 | unknown |
No description available.
|
| CVE-2018-7767 | 0.0 | unknown |
No description available.
|
| CVE-2018-7246 | 0.0 | unknown |
No description available.
|
| CVE-2017-5753 | 0.0 | unknown |
No description available.
|
| CVE-2017-0145 | 0.0 | unknown |
No description available.
|
| CVE-2017-0148 | 0.0 | unknown |
No description available.
|
| CVE-2018-15361 | 0.0 | unknown |
CVE-2018-15361. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6810 | 0.0 | unknown |
An improper access control vulnerability exists that could allow the execution of commands by unauthorized users when using the IEC 60870-5-104 protocol.CVE-2019-6810 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).
|
| CVE-2018-7814 | 0.0 | unknown |
No description available.
|
| CVE-2018-7804 | 0.0 | unknown |
No description available.
|
| CVE-2018-7774 | 0.0 | unknown |
No description available.
|
| CVE-2019-6834 | 0.0 | unknown |
No description available.
|
| CVE-2018-7796 | 0.0 | unknown |
No description available.
|
| CVE-2019-6819 | 0.0 | unknown |
No description available.
|
| CVE-2017-7967 | 0.0 | unknown |
No description available.
|
| CVE-2019-13537 | 0.0 | unknown |
No description available.
|
| CVE-2018-7842 | 0.0 | unknown |
CVE-2018-7842. An authentication bypass by spoofing vulnerability exists which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
|
| CVE-2019-0708 | 0.0 | unknown |
The affected product is vulnerable to a remote code execution vulnerability that exists in Remote Desktop Services (formerly known as Terminal Services) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system 's Remote Desktop Service via RDP.CVE-2019-0708 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2018-7239 | 0.0 | unknown |
No description available.
|
| CVE-2019-6806 | 0.0 | unknown |
CVE-2019-6806. An information exposure vulnerability exists which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
|
| CVE-2015-2290 | 0.0 | unknown |
No description available.
|
| CVE-2014-7187 | 0.0 | unknown |
No description available.
|
| CVE-2018-7769 | 0.0 | unknown |
No description available.
|
| CVE-2019-6853 | 0.0 | unknown |
No description available.
|
| CVE-2018-7830 | 0.0 | unknown |
No description available.
|
| CVE-2017-0144 | 0.0 | unknown |
No description available.
|
| CVE-2018-7783 | 8.6 | high |
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. This vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.CVE-2018-7783 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2019-12264 | 0.0 | unknown |
This vulnerability requires that at least one IPv4 multicast address has been assigned to the target in an incorrect way (e.g., using the API intended for assigning unicast addresses). An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task.. CVE-2019-12259 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.
|
| CVE-2019-6847 | 0.0 | unknown |
No description available.
|
| CVE-2018-7762 | 0.0 | unknown |
No description available.
|
| CVE-2019-8264 | 0.0 | unknown |
CVE-2019-8264. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2017-9958 | 0.0 | unknown |
No description available.
|
| CVE-2018-7833 | 0.0 | unknown |
No description available.
|
| CVE-2017-9968 | 0.0 | unknown |
No description available.
|
| CVE-2019-8274 | 0.0 | unknown |
CVE-2019-8274. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6835 | 0.0 | unknown |
No description available.
|
| CVE-2019-6831 | 0.0 | unknown |
An improper check for unusual or exceptional conditions vulnerability exists that could cause disconnection of active connections when an unusually high number of IEC 60870-5-104 packets are received by the module on Port 2404/TCP.CVE-2019-6831 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2017-0146 | 0.0 | unknown |
No description available.
|
| CVE-2019-6839 | 0.0 | unknown |
No description available.
|
| CVE-2017-6034 | 0.0 | unknown |
No description available.
|
| CVE-2018-7766 | 0.0 | unknown |
No description available.
|
| CVE-2019-6815 | 0.0 | unknown |
No description available.
|
| CVE-2018-12130 | 0.0 | unknown |
CVE-2018-12130. Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing
speculative execution may allow an authenticated user to potentially enable information disclosure via
a side channel with local access.
Additional information about the vulnerabilities can be found in the INTEL website:
[INTEL-SA-00233](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html)
|
| CVE-2018-7855 | 0.0 | unknown |
CVE-2018-7855. An uncaught exception vulnerability exists, which could cause a denial of service when sending invalid breakpoint parameters to the controller over Modbus.
|
| CVE-2018-12126 | 0.0 | unknown |
No description available.
|
| CVE-2015-7921 | 0.0 | unknown |
The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.
|
| CVE-2017-9956 | 0.0 | unknown |
No description available.
|
| CVE-2018-7784 | 0.0 | unknown |
No description available.
|
| CVE-2018-7853 | 0.0 | unknown |
CVE-2018-7853. An uncaught exception vulnerability exists, which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus.
|
| CVE-2017-7969 | 0.0 | unknown |
No description available.
|
| CVE-2014-9188 | 0.0 | unknown |
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.
|
| CVE-2019-6842 | 0.0 | unknown |
No description available.
|
| CVE-2019-8270 | 0.0 | unknown |
CVE-2019-8270. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7848 | 0.0 | unknown |
CVE-2018-7848. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading files from the controller over Modbus.
|
| CVE-2017-7971 | 0.0 | unknown |
No description available.
|
| CVE-2017-9960 | 0.0 | unknown |
No description available.
|
| CVE-2019-8259 | 0.0 | unknown |
CVE-2019-8259. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6845 | 0.0 | unknown |
No description available.
|
| CVE-2019-8277 | 0.0 | unknown |
CVE-2019-8277. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7815 | 0.0 | unknown |
No description available.
|
| CVE-2018-7790 | 0.0 | unknown |
No description available.
|
| CVE-2018-7847 | 0.0 | unknown |
CVE-2018-7847. An improper access control vulnerability exists which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
|
| CVE-2019-6827 | 0.0 | unknown |
No description available.
|
| CVE-2019-8260 | 0.0 | unknown |
CVE-2019-8260. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6821 | 0.0 | unknown |
No description available.
|
| CVE-2018-7764 | 0.0 | unknown |
No description available.
|
| CVE-2019-8271 | 0.0 | unknown |
CVE-2019-8271. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2019-6813 | 0.0 | unknown |
An improper check for unusual or exceptional conditions vulnerability exists that could cause a denial-of-service condition when truncated SNMP packets on Port 161/UDP are received by the device.CVE-2019-6813 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2018-7823 | 0.0 | unknown |
No description available.
|
| CVE-2019-6844 | 0.0 | unknown |
No description available.
|
| CVE-2018-7831 | 0.0 | unknown |
No description available.
|
| CVE-2014-8512 | 0.0 | unknown |
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.
|
| CVE-2016-2292 | 0.0 | unknown |
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
|
| CVE-2019-6851 | 0.0 | unknown |
No description available.
|
| CVE-2017-3651 | 0.0 | unknown |
No description available.
|
| CVE-2018-7779 | 0.0 | unknown |
No description available.
|
| CVE-2019-1225 | 0.0 | unknown |
No description available.
|
| CVE-2019-12265 | 0.0 | unknown |
The IGMPv3 reception handler does not expect packets to be spread across multiple IP-fragments.CVE-2019-12265 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
|
| CVE-2014-7186 | 0.0 | unknown |
No description available.
|
| CVE-2018-7810 | 0.0 | unknown |
No description available.
|
| CVE-2018-7845 | 0.0 | unknown |
CVE-2018-7845. An out-of-bounds read vulnerability exists, which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
|
| CVE-2018-7776 | 0.0 | unknown |
No description available.
|
| CVE-2017-9970 | 0.0 | unknown |
No description available.
|
| CVE-2018-7786 | 0.0 | unknown |
No description available.
|
| CVE-2017-5754 | 0.0 | unknown |
No description available.
|
| CVE-2018-7758 | 0.0 | unknown |
No description available.
|
| CVE-2019-6841 | 0.0 | unknown |
No description available.
|
| CVE-2019-8262 | 0.0 | unknown |
CVE-2019-8262. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7801 | 0.0 | unknown |
No description available.
|
| CVE-2019-10981 | 0.0 | unknown |
No description available.
|
| CVE-2019-6823 | 0.0 | unknown |
No description available.
|
| CVE-2019-6822 | 0.0 | unknown |
No description available.
|
| CVE-2019-8266 | 0.0 | unknown |
CVE-2019-8266. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2017-7970 | 0.0 | unknown |
No description available.
|
| CVE-2018-7795 | 0.0 | unknown |
No description available.
|
| CVE-2019-6824 | 0.0 | unknown |
No description available.
|
| CVE-2018-7813 | 0.0 | unknown |
No description available.
|
| CVE-2018-7777 | 0.0 | unknown |
No description available.
|
| CVE-2018-7798 | 0.0 | unknown |
No description available.
|
| CVE-2019-1226 | 0.0 | unknown |
No description available.
|
| CVE-2019-6832 | 0.0 | unknown |
No description available.
|
| CVE-2018-7244 | 0.0 | unknown |
No description available.
|
| CVE-2016-6273 | 0.0 | unknown |
No description available.
|
| CVE-2019-6836 | 0.0 | unknown |
No description available.
|
| CVE-2019-8276 | 0.0 | unknown |
CVE-2019-8276. UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.
|
| CVE-2018-7850 | 0.0 | unknown |
CVE-2018-7850. A reliance on untrusted inputs in a security decision vulnerability exists which could cause invalid information displayed in Unity Pro software.
|
| CVE-2014-6271 | 0.0 | unknown |
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
|
| CVE-2018-7837 | 0.0 | unknown |
No description available.
|
| CVE-2017-5715 | 0.0 | unknown |
CVE-2017-5715. An attacker with local access to the system could potentially disclose information
from protected memory areas via a side-channel attack on the processor cache.
|
| CVE-2018-12127 | 0.0 | unknown |
No description available.
|
| CVE-2018-7841 | 0.0 | unknown |
No description available.
|
| CVE-2015-3962 | 0.0 | unknown |
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.
|
| CVE-2014-6278 | 0.0 | unknown |
No description available.
|
| CVE-2018-7771 | 0.0 | unknown |
No description available.
|
| CVE-2019-6828 | 0.0 | unknown |
CVE-2019-6828. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
|
| CVE-2019-12258 | 0.0 | unknown |
An attacker with the source and destination TCP-port and IP-addresses of a session can inject invalid TCP segments into the flow, causing the TCP-session to be reset. An application will see this as an ECONNRESET error message when using the socket after such an attack. The most likely outcome is a crash of the application reading from the affected socket.. CVE-2019-12258 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).The most likely outcome is a crash of the application reading from the affected socket.
|
| CVE-2019-12255 | 0.0 | unknown |
An attacker can either hijack an existing TCP session and inject bad TCP segments or establish a new TCP session on any TCP port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12255 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2018-7788 | 0.0 | unknown |
No description available.
|
| CVE-2018-7778 | 0.0 | unknown |
No description available.
|
| CVE-2018-7836 | 0.0 | unknown |
No description available.
|
| CVE-2019-6829 | 0.0 | unknown |
CVE-2019-6829. An uncaught exception vulnerability exists which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
|
| CVE-2019-6840 | 0.0 | unknown |
No description available.
|
| CVE-2018-7785 | 0.0 | unknown |
No description available.
|
| CVE-2018-7851 | 0.0 | unknown |
No description available.
|
| CVE-2019-6854 | 0.0 | unknown |
No description available.
|
| CVE-2019-12263 | 0.0 | unknown |
This vulnerability relies on a race-condition between the network task (tNet0) and the receiving application. It is very difficult to trigger the race on a system with a single CPU-thread enabled, and there is no way to reliably trigger a race on SMP targets.CVE-2019-12263 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2018-7817 | 0.0 | unknown |
No description available.
|
| CVE-2018-7768 | 0.0 | unknown |
No description available.
|
| CVE-2018-7857 | 0.0 | unknown |
CVE-2018-7857. An uncaught exception vulnerability exists, which could cause a possible denial of service when writing out of bounds variables to the controller over Modbus.
|
| CVE-2019-6826 | 0.0 | unknown |
No description available.
|
| CVE-2017-3641 | 0.0 | unknown |
No description available.
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | hmi |
L2
|
-- |
| Siemens | Unknown | hmi |
L2
|
-- |
| Siemens | Unknown | hmi |
L2
|
-- |
| Siemens | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | rtu |
L1
|
vers:all/* |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens | Unknown | network_device | -- | -- |
| ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens | Unknown | scada_server |
L2
|
-- |
| ABB ; Cisco ; Digi ; eWON ; Meinberg ; Moxa ; Red Lion; Siemens | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |