CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Electric_fr_configurator2_firmware, Electric_fr_configurator2, Qj71e71-100_firmware, Qj71e71-100, Q03/04/06/13/26udvcpu_firmware, Q03/04/06/13/26udvcpu, Q04/06/13/26udpvcpu_firmware, Q04/06/13/26udpvcpu, Q03udecpu_firmware, Q03udecpu
2020-10-02
N/A
7.5 HIGH
In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition.
Electric_fr_configurator2_firmware, Electric_fr_configurator2, Qj71e71-100_firmware, Qj71e71-100, Q03/04/06/13/26udvcpu_firmware, Q03/04/06/13/26udvcpu, Q04/06/13/26udpvcpu_firmware, Q04/06/13/26udpvcpu, Q03udecpu_firmware, Q03udecpu
2019-10-09
N/A
5.5 MEDIUM
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.
2019-10-09
N/A
6.6 MEDIUM
An out-of-bounds read vulnerability has been identified in Fuji Electric Alpha7 PC Loader Versions 1.1 and prior, which may crash the system.
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
Electric_fr_configurator2_firmware, Electric_fr_configurator2, Qj71e71-100_firmware, Qj71e71-100, Q03/04/06/13/26udvcpu_firmware, Q03/04/06/13/26udvcpu, Q04/06/13/26udpvcpu_firmware, Q04/06/13/26udpvcpu, Q03udecpu_firmware, Q03udecpu
2020-10-02
N/A
5.5 MEDIUM
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.
Compactlogix_5370_l1_firmware, Compactlogix_5370_l1, Compactlogix_5370_l2_firmware, Compactlogix_5370_l2, Compactlogix_5370_l3_firmware, Compactlogix_5370_l3, Armor_compact_guardlogix_5370_firmware, Armor_compact_guardlogix_5370, Compact_guardlogix_5370_firmware, Compact_guardlogix_5370
2020-10-01
N/A
9.8 CRITICAL
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may boot-up the terminal and gain root-level access to the device’s file system.
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1093.
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2019-10-23
N/A
7.2 HIGH
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.
