Page 2 of 17 results (0.007 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

26 Jun 2024 — An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL. Se descubrió un problema en los dispositivos HMS Anybus X-Gateway AB7832-F 3. • https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway • CWE-598: Use of GET Request Method With Sensitive Query Strings •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

26 Jun 2024 — An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations. Se descubrió un problema en la versión 3 del firmware HMS Anybus X-Gateway AB7832-F. El protocolo HICP permite cambios no autenticados en las configuraciones de red de un dispositivo. • https://sensepost.com/blog/2024/targeting-an-industrial-protocol-gateway • CWE-287: Improper Authentication •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

09 Jul 2021 — In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation. En HMS Ewon eCatcher versiones hasta 6.6.4, permisos débiles del sistema de archivos podrían permitir a usuarios maliciosos acceder a archivos que podrían conllevar a una divulgación de información confidencial, la modificación de archivos de configuración o la interrupci... • https://cdn.hms-networks.com/docs/librariesprovider6/cybersecurity/hms-security-advisory-2021-07-09-001---ewon-ecatcher.pdf?sfvrsn=b37418d7_4 • CWE-276: Incorrect Default Permissions •

CVSS: 2.3EPSS: 0%CPEs: 4EXPL: 0

18 Sep 2020 — All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing. Todas las versiones de Ewon Flexy Cozy versiones anteriores a la 14.1, usan comodines tales como (*) bajo los cuales los dominios pueden soli... • https://us-cert.cisa.gov/ics/advisories/icsa-20-254-03 •

CVSS: 10.0EPSS: 2%CPEs: 1EXPL: 0

26 Aug 2020 — HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. HMS Industrial Networks AB eCatcher todas las versiones anteriores a 6.5.5. El producto afectado es vulnerable a un desbordamiento del búfer en la región stack de la memoria, lo que puede permitir a un atacante ejecutar código arbitrario remotamente • https://us-cert.cisa.gov/ics/advisories/icsa-20-210-03 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

08 Apr 2020 — A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful. Se presenta una vulnerabilidad de tipo XSS (cross-site scripting) no persistente en eWON Flexy y Cozy (todas las versiones de firmware anteriores a 14.1s0). Un atacante podría enviar una URL espec... • https://www.us-cert.gov/ics/advisories/icsa-20-098-03 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 16EXPL: 3

13 Jan 2019 — HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. Los dispositivos HMS Industrial Networks Netbiter WS100 3.30.5 y anteriores tienen Cross-Site Scripting (XSS) reflejado en el formulario de inicio de sesión. HMS Netbiter WS100 versions 3.30.5 and below suffer from a cross site scripting vulnerability. • https://packetstorm.news/files/id/151119 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •