CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
2021-03-23
N/A
6.1 MEDIUM
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.
Sentinel_ldk_license_manager, 20007_office_system, 27mhz_wireless_keyboard, 365_apps, 3d_builder, 3d_viewer, Access, Accessibility_insights_for_android, Accessibility_insights_for_web, Access_multilingual_user_interface_pack, Active_directory
2019-12-19
N/A
7.8 HIGH
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege escalation. This vulnerability could also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.
2021-03-23
N/A
7.5 HIGH
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.
Hbd3pr2_firmware, Hbd3pr2, H4d3prv3_firmware, H4d3prv3, Hed3pr3_firmware, Hed3pr3, H4d3prv2_firmware, H4d3prv2, Hbd3pr1_firmware, Hbd3pr1
2019-11-05
N/A
7.5 HIGH
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.
Hbd3pr2_firmware, Hbd3pr2, H4d3prv3_firmware, H4d3prv3, Hed3pr3_firmware, Hed3pr3, H4d3prv2_firmware, H4d3prv2, Hbd3pr1_firmware, Hbd3pr1
2020-09-29
N/A
7.5 HIGH
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.
Hbd3pr2_firmware, Hbd3pr2, H4d3prv3_firmware, H4d3prv3, Hed3pr3_firmware, Hed3pr3, H4d3prv2_firmware, H4d3prv2, Hbd3pr1_firmware, Hbd3pr1
2020-09-29
N/A
9.8 CRITICAL
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
Netscaler_gateway_firmware, Netscaler_gateway, Netscaler_application_delivery_controller_firmware, Netscaler_application_delivery_controller, Application_delivery_controller_firmware, Application_delivery_controller, Gateway_firmware, Gateway, 4000-wo, 4100-wo
2020-08-24
N/A
9.8 CRITICAL
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name.
