|
247211
|
7.5 |
HIGH
Network
|
siemens
|
simatic_hmi_comfort_panels_firmware simatic_hmi_comfort_outdoor_panels_firmware simatic_hmi_ktp_mobile_panels_ktp400f_firmware simatic_hmi_ktp_mobile_panels_ktp700_firmware simatic_hmi_kt…
|
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mo…
|
CWE-22
Path Traversal
|
CVE-2018-13812
|
2024-11-21 12:48 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247212
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_step_7_\(tia_portal\)
|
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file a…
|
CWE-200
Information Exposure
|
CVE-2018-13811
|
2024-11-21 12:48 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247213
|
8.1 |
HIGH
Network
|
siemens
|
simatic_it_ua_discrete_manufacturing simatic_it_production_suite simatic_it_line_monitoring_system
|
A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Di…
|
NVD-CWE-noinfo
|
CVE-2018-13804
|
2024-11-21 12:48 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247214
|
10.0 |
CRITICAL
Network
|
siemens
|
tim_1531_irc_firmware
|
A vulnerability has been identified in TIM 1531 IRC (All version < V2.0). The devices was missing proper authentication on port 102/tcp, although configured. Successful exploitation requires an attac…
|
CWE-287
Improper Authentication
|
CVE-2018-13816
|
2024-11-21 12:48 |
2018-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247215
|
7.5 |
HIGH
Network
|
descor
|
infocad_fm
|
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
|
CWE-287 CWE-294 CWE-522
Improper Authentication Authentication Bypass by Capture-replay Insufficiently Protected Credentials
|
CVE-2018-13789
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247216
|
8.8 |
HIGH
Network
|
siemens
|
rox_ii_firmware
|
A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user credentials for the target device could perform a …
|
CWE-269
Improper Privilege Management
|
CVE-2018-13801
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247217
|
7.5 |
HIGH
Network
|
siemens
|
simatic_et_200sp_firmware simatic_s7-1500_firmware simatic_s7-1500f_firmware
|
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 inc…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-13805
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247218
|
7.2 |
HIGH
Network
|
siemens
|
rox_ii_firmware
|
A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH could circumvent restrictions in place and execute…
|
CWE-269
Improper Privilege Management
|
CVE-2018-13802
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247219
|
7.3 |
HIGH
Network
|
siemens
|
simatic_s7-1200_v4_firmware
|
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user i…
|
CWE-352
Origin Validation Error
|
CVE-2018-13800
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247220
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-809_a1_firmware dir-809_a2_firmware dir-809_guestzone_firmware
|
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-14081
|
2024-11-21 12:48 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|