|
251851
|
5.3 |
MEDIUM
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.
|
CWE-200
Information Exposure
|
CVE-2017-6040
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251852
|
7.1 |
HIGH
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests wer…
|
CWE-352
Origin Validation Error
|
CVE-2017-6038
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251853
|
9.8 |
CRITICAL
Network
|
marel
|
a320_firmware a325_firmware a371_firmware a520_master_firmware a520_slave_firmware a530_firmware a542_firmware a571_firmware check_bin_grader_firmware flowlineqc_t376_firmw…
|
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check B…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-6041
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251854
|
6.5 |
MEDIUM
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently veri…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-6036
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251855
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modbus_firmware
|
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which …
|
CWE-287
Improper Authentication
|
CVE-2017-6034
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251856
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
modbus_firmware
|
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-f…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2017-6032
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251857
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_m241_firmware modicon_m251_firmware
|
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are se…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-6028
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251858
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
modicon_m241_firmware modicon_m251_firmware modicon_m221_firmware
|
A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior …
|
CWE-331
Insufficient Entropy
|
CVE-2017-6030
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251859
|
9.1 |
CRITICAL
Network
|
schneider-electric
|
modicon_m251_firmware modicon_m241_firmware
|
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to V…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-6026
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251860
|
9.8 |
CRITICAL
Network
|
bd
|
performa kla_journal_service
|
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use ha…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-6022
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|