|
246891
|
6.7 |
MEDIUM
Local
|
schneider-electric
|
igss_mobile
|
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in expo…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-9969
|
2024-11-21 12:37 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246892
|
5.9 |
MEDIUM
Network
|
schneider-electric
|
igss_mobile
|
A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establish…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-9968
|
2024-11-21 12:37 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246893
|
7.8 |
HIGH
Local
|
schneider-electric
|
interactive_graphical_scada_system
|
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) a…
|
NVD-CWE-noinfo
|
CVE-2017-9967
|
2024-11-21 12:37 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246894
|
8.1 |
HIGH
Network
|
schneider-electric
|
powerscada_anywhere
|
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2…
|
CWE-352
Origin Validation Error
|
CVE-2017-9963
|
2024-11-21 12:37 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246895
|
6.5 |
MEDIUM
Network
|
cisco
|
email_security_appliance_firmware content_security_management_appliance
|
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-0140
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246896
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense
|
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an…
|
CWE-693
Protection Mechanism Failure
|
CVE-2018-0138
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246897
|
8.6 |
HIGH
Network
|
cisco
|
prime_network
|
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabil…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-0137
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246898
|
4.3 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affec…
|
CWE-20
Improper Input Validation
|
CVE-2018-0135
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246899
|
5.3 |
MEDIUM
Network
|
cisco
|
mobility_services_engine
|
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2018-0134
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246900
|
8.6 |
HIGH
Network
|
cisco
|
carrier_routing_system
|
A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0132
|
2024-11-21 12:37 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|