|
247481
|
4.4 |
MEDIUM
Adjacent
|
medtronic
|
mycarelink_24952_patient_monitor_firmware mycarelink_24950_patient_monitor_firmware
|
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected product's update service does not sufficiently verify the authenticity of the data…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2018-10626
|
2024-11-21 12:41 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247482
|
7.1 |
HIGH
Physics
|
medtronic
|
mycarelink_24952_patient_monitor_firmware mycarelink_24950_patient_monitor_firmware
|
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient Monitor. The affected products use per-product credentials that are stored in a recoverable format. An a…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-10622
|
2024-11-21 12:41 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247483
|
6.5 |
MEDIUM
Adjacent
|
johnsoncontrols
|
bcpro metasys_system
|
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the se…
|
CWE-388
7PK - Errors
|
CVE-2018-10624
|
2024-11-21 12:41 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247484
|
9.8 |
CRITICAL
Network
|
davolink
|
dvw-3200n_firmware
|
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2018-10618
|
2024-11-21 12:41 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247485
|
6.1 |
MEDIUM
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code e…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10609
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247486
|
7.5 |
HIGH
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a deni…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-10607
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247487
|
9.8 |
CRITICAL
Network
|
martem
|
telem-gwm_firmware telem-gw6_firmware
|
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the …
|
CWE-287
Improper Authentication
|
CVE-2018-10603
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247488
|
9.8 |
CRITICAL
Network
|
yokogawa
|
fcj_firmware fcn-100_firmware fcn-rtu_firmware fcn-500_firmware
|
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10592
|
2024-11-21 12:41 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247489
|
9.8 |
CRITICAL
Network
|
aveva
|
intouch_2017 intouch_2014
|
AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10628
|
2024-11-21 12:41 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247490
|
7.5 |
HIGH
Network
|
moxa
|
nport_5230_firmware nport_5232_firmware nport_5210_firmware
|
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-10632
|
2024-11-21 12:41 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|