Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:
- C-CURE 9000 and victor <=v2.90_v3.0
- victor Web <=v7.1
Summary
Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users.
The following versions of Weintek cMT3092X are affected:
- cMT3092X firmware <20210218
- EasyWeb <v2.1.20
| CVSS | … |
|---|
Summary
Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service.
The following versions of MZ Automation lib60870 are affected:
- lib60870 <=2.4.0
| CVSS | Vendor | Equipment | … |
|---|
Summary
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.
The following versions of Rockwell Automation ThinManager are affected:
- ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2
Summary
Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.
The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected:
- 1718/ 1719 Ex I/O 3.011
| CVSS | Vendor | … |
|---|
Summary
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
The following …
Summary
Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations.
The following versions of Rockwell Automation FactoryTalk Services Platform are affected:
- FactoryTalk Directory (FTSP) 6.60