|
246381
|
10.0 |
CRITICAL
Network
|
siemens
|
tim_1531_irc_firmware
|
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attac…
|
CWE-287
Improper Authentication
|
CVE-2018-13816
|
2024-11-21 12:48 |
2018-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246382
|
7.5 |
HIGH
Network
|
descor
|
infocad_fm
|
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
|
CWE-287 CWE-294 CWE-522
Improper Authentication Authentication Bypass by Capture-replay Insufficiently Protected Credentials
|
CVE-2018-13789
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246383
|
8.8 |
HIGH
Network
|
siemens
|
rox_ii_firmware
|
A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user credentials for the target device could perform a …
|
CWE-269
Improper Privilege Management
|
CVE-2018-13801
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246384
|
7.5 |
HIGH
Network
|
siemens
|
simatic_et_200sp_firmware simatic_s7-1500_firmware simatic_s7-1500f_firmware
|
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 inc…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-13805
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246385
|
7.2 |
HIGH
Network
|
siemens
|
rox_ii_firmware
|
A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH could circumvent restrictions in place and execute…
|
CWE-269
Improper Privilege Management
|
CVE-2018-13802
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246386
|
7.3 |
HIGH
Network
|
siemens
|
simatic_s7-1200_v4_firmware
|
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user i…
|
CWE-352
Origin Validation Error
|
CVE-2018-13800
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246387
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-809_a1_firmware dir-809_a2_firmware dir-809_guestzone_firmware
|
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-14081
|
2024-11-21 12:48 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246388
|
7.5 |
HIGH
Network
|
d-link
|
dir-809_a1_firmware dir-809_a2_firmware dir-809_guestzone_firmware
|
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.
|
CWE-287
Improper Authentication
|
CVE-2018-14080
|
2024-11-21 12:48 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246389
|
6.1 |
MEDIUM
Network
|
progress
|
kendo_ui
|
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Seri…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14037
|
2024-11-21 12:48 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246390
|
7.8 |
HIGH
Local
|
ee
|
ee40vb_firmware
|
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Con…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14327
|
2024-11-21 12:48 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|