8 results (0.009 seconds)

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server. SUBNET Solutions Inc. ha identificado vulnerabilidades en componentes de terceros utilizados en Substation Server. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-128-02 • CWE-1357: Reliance on Insufficiently Trustworthy Component •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center. SUBNET Solutions Inc. ha identificado vulnerabilidades en componentes de terceros utilizados en PowerSYSTEM Center. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-02 • CWE-1357: Reliance on Insufficiently Trustworthy Component •

CVSS: 8.6EPSS: 0%CPEs: 2EXPL: 0

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021. SUBNET Solutions Inc. ha identificado vulnerabilidades en componentes de terceros utilizados en PowerSYSTEM Server 2021 y Substation Server 2021. • https://www.cisa.gov/news-events/ics-advisories/icsa-24-100-01 • CWE-1357: Reliance on Insufficiently Trustworthy Component •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges. Las versiones 2020 Update 16 y anteriores de PowerSYSTEM Center contienen una vulnerabilidad que puede permitir que un usuario local autorizado inserte código arbitrario en la ruta del servicio sin comillas y escale privilegios. • https://subnet.com/contact https://www.cisa.gov/news-events/ics-advisories/icsa-23-353-01 • CWE-428: Unquoted Search Path or Element •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-166-01 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •