|
250291
|
9.8 |
CRITICAL
Network
|
binom3
|
universal_multifunctional_electric_power_quality_meter_firmware
|
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An INFORMATION EXPOSURE flaw can be used to gain privileged access to the device.
|
CWE-200
Information Exposure
|
CVE-2017-5166
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250292
|
7.6 |
HIGH
Network
|
binom3
|
universal_multifunctional_electric_power_quality_meter_firmware
|
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vu…
|
CWE-352
Origin Validation Error
|
CVE-2017-5165
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250293
|
6.1 |
MEDIUM
Network
|
binom3
|
universal_multifunctional_electric_power_quality_meter_firmware
|
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2017-5164
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250294
|
5.9 |
MEDIUM
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, whi…
|
CWE-22
Path Traversal
|
CVE-2017-5163
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250295
|
9.8 |
CRITICAL
Network
|
binom3
|
universal_multifunctional_electric_power_quality_meter_firmware
|
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-5162
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250296
|
7.2 |
HIGH
Local
|
sielcosistemi
|
winlog_lite winlog_pro
|
An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01. An uncontrolled search path …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-5161
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250297
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
mguard_firmware
|
An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succ…
|
CWE-99
Resource Injection
|
CVE-2017-5159
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250298
|
6.1 |
MEDIUM
Network
|
schneider_electric
|
homelynk_controller_lss100100_firmware
|
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5157
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250299
|
7.3 |
HIGH
Network
|
schneider-electric
|
wonderware_historian
|
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compr…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2017-5155
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250300
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack…
|
CWE-89
SQL Injection
|
CVE-2017-5154
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|