• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-6984
Micrologix 1400 B Firmware, Rockwellautomation
Compactlogix_5370_l1_firmware, Compactlogix_5370_l1, Compactlogix_5370_l2_firmware, Compactlogix_5370_l2, Compactlogix_5370_l3_firmware, Compactlogix_5370_l3, Armor_compact_guardlogix_5370_firmware, Armor_compact_guardlogix_5370, Compact_guardlogix_5370_firmware, Compact_guardlogix_5370
2020-03-20
N/A
7.5 HIGH
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.
CVE-2020-6983
2020-03-26
N/A
7.5 HIGH
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.
CVE-2020-6982
2020-03-26
N/A
8.8 HIGH
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.
CVE-2020-6981
Eds-g516e, Moxa
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2020-03-26
N/A
9.8 CRITICAL
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.
CVE-2020-6980
Micrologix 1400 A Firmware, Rockwellautomation
Compactlogix_5370_l1_firmware, Compactlogix_5370_l1, Compactlogix_5370_l2_firmware, Compactlogix_5370_l2, Compactlogix_5370_l3_firmware, Compactlogix_5370_l3, Armor_compact_guardlogix_5370_firmware, Armor_compact_guardlogix_5370, Compact_guardlogix_5370_firmware, Compact_guardlogix_5370
2020-03-20
N/A
3.3 LOW
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.
CVE-2020-6979
Eds-g516e, Moxa
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2020-03-26
N/A
7.5 HIGH
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.
CVE-2020-6978
2020-03-27
N/A
7.2 HIGH
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.
CVE-2020-6977
2020-03-05
N/A
6.8 MEDIUM
A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5
CVE-2020-6976
Cncsoft Screeneditor, Deltaww
Asda_soft, Cncsoft, Cncsoft-b, Cncsoft_screeneditor, Cnssoft_screeneditor, Commgr, Dcisoft, Delta_industrial_automation_dopsoft, Delta_industrial_automation_pmsoft, Delta_industrial_automation_screen_editor
2020-03-20
N/A
5.5 MEDIUM
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.
CVE-2020-6975
2020-02-21
N/A
4.9 MEDIUM
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2. Successful exploitation of this vulnerability could allow an attacker to upload a malicious file to the application.
« Previous 1 … 3,301 3,302 3,303 3,304 3,305 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE