In ifm Smart PLC firmware up to version 4.3.17 for Smart PLC controllers AC14xx and AC4xxS, an attacker can access the configuration by using the hardcoded credentials. The endpoint hosts a scripts capable of executing various commands.
moneo "Forgot Password" function has a vulnerability which allows gaining privileged access.
An unauthenticated remote attacker could reset the administrator's password with information from the default, self-signed certificate.