Page 2 of 9 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01 • CWE-798: Use of Hard-coded Credentials •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

PiiGAB M-Bus transmits credentials in plaintext format. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01 • CWE-523: Unprotected Transport of Credentials •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01 • CWE-307: Improper Restriction of Excessive Authentication Attempts •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-187-01 • CWE-94: Improper Control of Generation of Code ('Code Injection') •