|
246501
|
7.5 |
HIGH
Network
|
pharoscontrols
|
pharos_firmware
|
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.
|
CWE-200
Information Exposure
|
CVE-2018-12926
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246502
|
9.8 |
CRITICAL
Network
|
lantronix
|
mss_firmware
|
Baseon Lantronix MSS devices do not require a password for TELNET access.
|
CWE-521
Weak Password Requirements
|
CVE-2018-12925
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246503
|
9.8 |
CRITICAL
Network
|
eztcp
|
cie-h10_firmware cie-h12_firmware cie-h14_firmware cse-m53n_firmware cse-m32_firmware cse-m24_firmware cse-m73_firmware cse-b63n2_firmware
|
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-12924
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246504
|
7.5 |
HIGH
Network
|
bwssystems
|
ha_bridge
|
BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.
|
CWE-200
Information Exposure
|
CVE-2018-12923
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246505
|
7.5 |
HIGH
Network
|
vertiv
|
liebert_intellislot_firmware
|
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelnet.htm URI.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12922
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246506
|
7.5 |
HIGH
Network
|
electroind
|
gaugetech_nexus_firmware
|
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.…
|
CWE-200
Information Exposure
|
CVE-2018-12921
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246507
|
7.5 |
HIGH
Network
|
flir
|
brickstream_2300_firmware
|
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.
|
CWE-200
Information Exposure
|
CVE-2018-12920
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246508
|
6.1 |
MEDIUM
Network
|
craftedweb_project
|
craftedweb
|
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12919
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246509
|
9.8 |
CRITICAL
Network
|
pbc_project
|
pbc
|
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12918
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246510
|
9.8 |
CRITICAL
Network
|
pbc_project
|
pbc
|
In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12917
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|