2 results (0.006 seconds)

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

09 Jun 2021 — SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges. Un dispositivo SGE-PLC1000, en su versión de firmware 0.9.2b, no maneja algunas peticiónes correctamente, permitiendo a un atacante remoto inyectar código en el sistema operativo con máximos privilegios • https://www.incibe.es/en/incibe-cert/notices/aviso-sci/circutor-sge-plc1000-os-command-injection • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

09 Jun 2021 — Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located. Una vulnerabilidad de Autenticación Inapropiada en el parámetro cookies de Circutor SGE-PLC1000 versión del firmware 0.9.2b, permite a un atacante llevar a cabo operaciones como un usuario autenticado. Para explo... • https://www.incibe.es/en/incibe-cert/notices/aviso-sci/circutor-sge-plc1000-improper-authentication • CWE-565: Reliance on Cookies without Validation and Integrity Checking •