3 results (0.010 seconds)

CVSS: 5.9EPSS: 5%CPEs: 205EXPL: 1

25 Mar 2021 — An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS c... • https://github.com/riptl/cve-2021-3449 • CWE-476: NULL Pointer Dereference •

CVSS: 7.4EPSS: 0%CPEs: 17EXPL: 0

31 Jul 2013 — Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship. Los dispositivos Siemens Scalance W7xx con firmware anterior a 4.5.4 utiliza el certificado X.509 embebido (hardcoded) para distintas instalaciones, lo que facilita a atacantes remotos llevar a cabo ataques man-in-the-... • http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-120908.pdf • CWE-255: Credentials Management Errors •

CVSS: 10.0EPSS: 0%CPEs: 17EXPL: 0

31 Jul 2013 — Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary code via a (1) SSH or (2) TELNET connection. Vulnerabilidad sin especificar en el interfaz de gestión de los dispositivos Siemens Scalance W7xx con firmware anterior a 4.5.4, permite a atacantes remotos evitar la autenticación y ejecutar código arbitrario a través de conexiones (1)SSH o (2)Telnet. • http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-120908.pdf •