|
246771
|
7.8 |
HIGH
Local
|
siemens
|
sipass_integrated
|
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to p…
|
NVD-CWE-noinfo
|
CVE-2017-9942
|
2024-11-21 12:37 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246772
|
7.4 |
HIGH
Network
|
siemens
|
sipass_integrated
|
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass in…
|
NVD-CWE-noinfo
|
CVE-2017-9941
|
2024-11-21 12:37 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246773
|
8.1 |
HIGH
Network
|
siemens
|
sipass_integrated
|
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file sy…
|
CWE-269
Improper Privilege Management
|
CVE-2017-9940
|
2024-11-21 12:37 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246774
|
9.8 |
CRITICAL
Network
|
siemens
|
sipass_integrated
|
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication m…
|
CWE-287
Improper Authentication
|
CVE-2017-9939
|
2024-11-21 12:37 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246775
|
7.5 |
HIGH
Network
|
siemens
|
simatic_logon
|
A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to caus…
|
CWE-20
Improper Input Validation
|
CVE-2017-9938
|
2024-11-21 12:37 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246776
|
7.5 |
HIGH
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout polici…
|
NVD-CWE-noinfo
|
CVE-2017-9864
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246777
|
8.8 |
HIGH
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in…
|
CWE-352
Origin Validation Error
|
CVE-2017-9863
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246778
|
7.5 |
HIGH
Network
|
sma
|
sunny_explorer
|
An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applicat…
|
CWE-200
Information Exposure
|
CVE-2017-9862
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246779
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, an…
|
CWE-74
Injection
|
CVE-2017-9861
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246780
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an…
|
CWE-287
Improper Authentication
|
CVE-2017-9860
|
2024-11-21 12:37 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|