CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Ie-sw-pl09m-5gc-4gt_firmware, Ie-sw-pl09m-5gc-4gt, Ie-sw-pl09mt-5gc-4gt_firmware, Ie-sw-pl09mt-5gc-4gt, Ie-sw-pl18m-2gc-16tx_firmware, Ie-sw-pl18m-2gc-16tx, Ie-sw-pl18mt-2gc-16tx_firmware, Ie-sw-pl18mt-2gc-16tx, Ie-sw-pl18m-2gc14tx2sc_firmware, Ie-sw-pl18m-2gc14tx2sc
2022-04-01
N/A
9.8 CRITICAL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
Ie-sw-pl09m-5gc-4gt_firmware, Ie-sw-pl09m-5gc-4gt, Ie-sw-pl09mt-5gc-4gt_firmware, Ie-sw-pl09mt-5gc-4gt, Ie-sw-pl18m-2gc-16tx_firmware, Ie-sw-pl18m-2gc-16tx, Ie-sw-pl18mt-2gc-16tx_firmware, Ie-sw-pl18mt-2gc-16tx, Ie-sw-pl18m-2gc14tx2sc_firmware, Ie-sw-pl18m-2gc14tx2sc
2019-12-12
N/A
6.5 MEDIUM
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Remote authenticated users can crash a device with a special packet because of Uncontrolled Resource Consumption.
Ie-sw-pl09m-5gc-4gt_firmware, Ie-sw-pl09m-5gc-4gt, Ie-sw-pl09mt-5gc-4gt_firmware, Ie-sw-pl09mt-5gc-4gt, Ie-sw-pl18m-2gc-16tx_firmware, Ie-sw-pl18m-2gc-16tx, Ie-sw-pl18mt-2gc-16tx_firmware, Ie-sw-pl18mt-2gc-16tx, Ie-sw-pl18m-2gc14tx2sc_firmware, Ie-sw-pl18m-2gc14tx2sc
2019-12-12
N/A
9.8 CRITICAL
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by connecting to the Graphite service and sending arbitrary data. A successful exploit could allow the attacker to write arbitrary data to Graphite, which could result in invalid statistics being presented in the interface. Versions prior to 3.5(2a) are affected.
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.
