|
246761
|
7.5 |
HIGH
Network
|
aveva
|
clearscada
|
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9962
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246762
|
7.8 |
HIGH
Local
|
schneider-electric
|
pro-face_gp_pro_ex
|
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. B…
|
NVD-CWE-noinfo
|
CVE-2017-9961
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246763
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
u.motion_builder
|
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should b…
|
CWE-200
Information Exposure
|
CVE-2017-9960
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246764
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
u.motion_builder
|
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of serv…
|
NVD-CWE-noinfo
|
CVE-2017-9959
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246765
|
7.8 |
HIGH
Local
|
schneider-electric
|
u.motion_builder
|
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attac…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-9958
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246766
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
u.motion_builder
|
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9957
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246767
|
7.3 |
HIGH
Network
|
schneider-electric
|
u.motion_builder
|
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9956
|
2024-11-21 12:37 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246768
|
6.5 |
MEDIUM
Adjacent
|
siemens
|
7km_pac_switched_ethernet_profinet_expansion_module_firmware
|
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local E…
|
CWE-20
Improper Input Validation
|
CVE-2017-9945
|
2024-11-21 12:37 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246769
|
6.1 |
MEDIUM
Network
|
osnexus
|
quantastor
|
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9979
|
2024-11-21 12:37 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246770
|
5.3 |
MEDIUM
Network
|
osnexus
|
quantastor
|
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this infor…
|
CWE-200
Information Exposure
|
CVE-2017-9978
|
2024-11-21 12:37 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|