
CVE-2024-38502 – Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows stored XSS
https://notcve.org/view.php?id=CVE-2024-38502
13 Aug 2024 — An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. • https://cert.vde.com/en/advisories/VDE-2024-033 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-38501 – Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows HTML injection
https://notcve.org/view.php?id=CVE-2024-38501
13 Aug 2024 — An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device. • https://cert.vde.com/en/advisories/VDE-2024-033 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-5849 – Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows reflected XSS
https://notcve.org/view.php?id=CVE-2024-5849
13 Aug 2024 — An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. • https://cert.vde.com/en/advisories/VDE-2024-033 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-6422 – Pepperl+Fuchs: OIT Products can be manipulated via unintended Telnet access
https://notcve.org/view.php?id=CVE-2024-6422
10 Jul 2024 — An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. Un atacante remoto no autenticado puede manipular el dispositivo a través de Telnet, detener procesos, leer, eliminar y cambiar datos. • https://cert.vde.com/en/advisories/VDE-2024-038 • CWE-306: Missing Authentication for Critical Function •

CVE-2024-6421 – Pepperl+Fuchs: Incorrectly configured FTP-Server in OIT Products
https://notcve.org/view.php?id=CVE-2024-6421
10 Jul 2024 — An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service. Un atacante remoto no autenticado puede leer información confidencial del dispositivo a través de un servicio FTP configurado incorrectamente. • https://cert.vde.com/en/advisories/VDE-2024-038 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2021-34565 – In WirelessHART-Gateway versions 3.0.7 to 3.0.9 hard-coded credentials have been found
https://notcve.org/view.php?id=CVE-2021-34565
31 Aug 2021 — In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. En PEPPERL+FUCHS WirelessHART-Gateway versiones 3.0.7 hasta 3.0.9, los servicios SSH y telnet están activos con credenciales embebidas • https://cert.vde.com/en-us/advisories/vde-2021-027 • CWE-798: Use of Hard-coded Credentials •

CVE-2021-34564 – In WirelessHART-Gateway versions 3.0.9 a vulnerability allows to read and write sensitive data in a cookie
https://notcve.org/view.php?id=CVE-2021-34564
31 Aug 2021 — Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9. Cualquier vulnerabilidad de robo de cookies dentro de la aplicación o el navegador permitiría a un atacante robar las credenciales del usuario al PEPPERL+FUCHS WirelessHART-Gateway versión 3.0.9 • https://cert.vde.com/en-us/advisories/vde-2021-027 • CWE-315: Cleartext Storage of Sensitive Information in a Cookie •

CVE-2021-34563 – In WirelessHART-Gateway versions 3.0.8 and 3.0.9 the HttpOnly flag is missing in a cookie which allows client-side javascript to modify it
https://notcve.org/view.php?id=CVE-2021-34563
31 Aug 2021 — In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. En PEPPERL+FUCHS WirelessHART-Gateway versiones 3.0.8 y 3.0.9, el atributo HttpOnly no es ajustado en una cookie. Esto permite que el valor de la cookie sea leído o establecido por el JavaScript del lado del cliente • https://cert.vde.com/en-us/advisories/vde-2021-027 • CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag •

CVE-2021-34562 – A vulnerability in WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response
https://notcve.org/view.php?id=CVE-2021-34562
31 Aug 2021 — In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. En PEPPERL+FUCHS WirelessHART-Gateway versión 3.0.8, es posible inyectar JavaScript arbitrario en la respuesta de la aplicación • https://cert.vde.com/en-us/advisories/vde-2021-027 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-34561 – A vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebinding
https://notcve.org/view.php?id=CVE-2021-34561
31 Aug 2021 — In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser. En PEPPERL+FUCHS WirelessHART-Gateway versiones anteriores a 3.0.8 incluyéndola, se presenta un problema grave, si la aplicación no es accesible externamente o usa restricciones de acceso basadas en IP. L... • https://cert.vde.com/en-us/advisories/vde-2021-027 • CWE-350: Reliance on Reverse DNS Resolution for a Security-Critical Action •