4 results (0.001 seconds)

CVSS: 8.7EPSS: 0%CPEs: 1EXPL: 0

The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-306: Missing Authentication for Critical Function •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 9.2EPSS: 0%CPEs: 1EXPL: 0

The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.7EPSS: 0%CPEs: 1EXPL: 0

The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-291-01 • CWE-522: Insufficiently Protected Credentials •