AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
›
Home›CVE Feed
Security Intelligence

Global CVE Feed

Sourced from NIST NVD · Auto-synced every 6 hours

2,506
Total CVEs
493
CRIT
1247
HIGH
675
MED
58
LOW
58 / 2506
CVE-2022-2788LOW

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.

Aug 19, 2022
3.9
CVE-2019-18994LOW

Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.

Dec 18, 2019
3.9
CVE-2017-9635LOW

Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to reverse the user's password. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

May 18, 2018
3.9
CVE-2023-37857LOW

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.

Aug 9, 2023
3.8
CVE-2021-22799LOW

A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1

Jan 28, 2022
3.8
CVE-2023-5461LOW

A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241584. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
3.7
CVE-2022-29832LOW

Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later, GX Works2 all versions and GX Developer versions 8.40S and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could obtain information about the project file for MELSEC safety CPU modules or project file for MELSEC Q/FX/L series with security setting.

Nov 25, 2022
3.7
CVE-2016-8344LOW

An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release 430, and Experion PKS, Release 431. Experion PKS does not properly validate input. By sending a specially crafted packet, an attacker could cause the process to terminate. A successful exploit would prevent firmware uploads to the Series-C devices.

Feb 13, 2017
3.7
CVE-2004-2626LOW

GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

Dec 31, 2004
3.7
CVE-2024-6620LOW

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398.

Jul 29, 2024
3.5
CVE-2023-5460LOW

A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. This issue affects some unknown processing of the component Modbus Data Packet Handler. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241583. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Oct 9, 2023
3.5
CVE-2019-19092LOW

ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

Apr 2, 2020
3.5
CVE-2019-19090LOW

For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

Apr 2, 2020
3.5
CVE-2019-13936LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13935LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13934LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2013-2299LOW

Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Aug 22, 2013
3.5
CVE-2013-0672LOW

Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.

Mar 21, 2013
3.5
CVE-2016-3155LOW

Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive information or modify data via unspecified vectors.

Mar 18, 2016
3.4
CVE-2023-3669LOW

A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.

Aug 3, 2023
3.3
CVE-2022-2966LOW

Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.

Dec 16, 2022
3.3
CVE-2022-1404LOW

Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

Aug 31, 2022
3.3
CVE-2020-12025LOW

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.

Jul 14, 2020
3.3
CVE-2020-6980LOW

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.

Mar 16, 2020
3.3
CVE-2019-13511LOW

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.

Aug 15, 2019
3.3
CVE-2018-17907LOW

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.

Nov 5, 2018
3.3
CVE-2016-9348LOW

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. A configuration file contains parameters that represent passwords in plaintext.

Feb 13, 2017
3.3
CVE-2016-5812LOW

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file.

Aug 24, 2016
3.3
CVE-2016-4527LOW

ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.

Jun 10, 2016
3.3
CVE-2016-4516LOW

ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.

Jun 10, 2016
3.3
CVE-2015-7836LOW

Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.

Oct 28, 2015
3.3
CVE-2015-0998LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

Mar 29, 2015
3.3
CVE-2012-4691LOW

Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.

Dec 18, 2012
3.3
CVE-2014-7251LOW

XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.

Dec 6, 2014
3.2
CVE-2023-2876LOW

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.

Jun 13, 2023
3.1
CVE-2020-16232LOW

In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.

Mar 18, 2022
2.8
CVE-2016-4511LOW

ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.

Jun 10, 2016
2.8
CVE-2023-4089LOW

On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.

Oct 17, 2023
2.7
CVE-2016-9338LOW

An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. Because of an Incorrect Permission Assignment for Critical Resource, users with administrator privileges may be able to remove all administrative users requiring a factory reset to restore ancillary web server function. Exploitation of this vulnerability will still allow the affected device to function in its capacity as a controller.

Feb 13, 2017
2.7
CVE-2006-2406LOW

Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.

May 16, 2006
2.6
CVE-2016-7960LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.

Oct 13, 2016
2.5
CVE-2016-5849LOW

Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.

Jul 4, 2016
2.5
CVE-2015-1015LOW

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.

Oct 6, 2015
2.1
CVE-2015-0988LOW

Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file.

Oct 6, 2015
2.1
CVE-2015-5084LOW

The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.

Aug 3, 2015
2.1
CVE-2015-1602LOW

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.

Apr 6, 2015
2.1
CVE-2015-0999LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.

Mar 29, 2015
2.1
CVE-2015-0996LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

Mar 29, 2015
2.1
CVE-2015-1599LOW

The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions by leveraging a filesystem architectural error.

Mar 7, 2015
2.1
CVE-2015-1598LOW

The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.

Mar 7, 2015
2.1
CVE-2015-1355LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

Feb 18, 2015
2.1
CVE-2014-5231LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.

Jan 14, 2015
2.1
CVE-2014-5398LOW

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Aug 28, 2014
2.1
CVE-2014-2381LOW

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.

Aug 28, 2014
2.1
CVE-2014-5233LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.

Jan 14, 2015
1.9
CVE-2014-5232LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.

Jan 14, 2015
1.9
CVE-2012-4693LOW

Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.

Dec 18, 2012
1.9
CVE-2015-1009LOW

Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.

Aug 1, 2015
1.7
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2022-2788LOW
3.9
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Trave…Aug 19, 2022›
CVE-2019-18994LOW
3.9
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions …Dec 18, 2019›
CVE-2017-9635LOW
3.9
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When A…May 18, 2018›
CVE-2023-37857LOW
3.8
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote a…Aug 9, 2023›
CVE-2021-22799LOW
3.8
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an …Jan 28, 2022›
CVE-2023-5461LOW
3.7
A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. …Oct 9, 2023›
CVE-2022-29832LOW
3.7
Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporatio…Nov 25, 2022›
CVE-2016-8344LOW
3.7
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS,…Feb 13, 2017›
CVE-2004-2626LOW
3.7
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to …Dec 31, 2004›
CVE-2024-6620LOW
3.5
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site sc…Jul 29, 2024›
CVE-2023-5460LOW
3.5
A vulnerability was found in Delta Electronics WPLSoft up to 2.51 and classified as problematic. Thi…Oct 9, 2023›
CVE-2019-19092LOW
3.5
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alt…Apr 2, 2020›
CVE-2019-19090LOW
3.5
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencry…Apr 2, 2020›
CVE-2019-13936LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13935LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13934LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2013-2299LOW
3.5
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before…Aug 22, 2013›
CVE-2013-0672LOW
3.5
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11…Mar 21, 2013›
CVE-2016-3155LOW
3.4
Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to…Mar 18, 2016›
CVE-2023-3669LOW
3.3
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local att…Aug 3, 2023›
CVE-2022-2966LOW
3.3
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versio…Dec 16, 2022›
CVE-2022-1404LOW
3.3
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while pro…Aug 31, 2022›
CVE-2020-12025LOW
3.3
Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml…Jul 14, 2020›
CVE-2020-6980LOW
3.3
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, …Mar 16, 2020›
CVE-2019-13511LOW
3.3
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION E…Aug 15, 2019›
CVE-2018-17907LOW
3.3
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with t…Nov 5, 2018›
CVE-2016-9348LOW
3.3
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-5812LOW
3.3
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cle…Aug 24, 2016›
CVE-2016-4527LOW
3.3
ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users …Jun 10, 2016›
CVE-2016-4516LOW
3.3
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which…Jun 10, 2016›
CVE-2015-7836LOW
3.3
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffi…Oct 28, 2015›
CVE-2015-0998LOW
3.3
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2012-4691LOW
3.3
Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attacke…Dec 18, 2012›
CVE-2014-7251LOW
3.2
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/T…Dec 6, 2014›
CVE-2023-2876LOW
3.1
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB RE…Jun 13, 2023›
CVE-2020-16232LOW
2.8
In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciou…Mar 18, 2022›
CVE-2016-4511LOW
2.8
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes…Jun 10, 2016›
CVE-2023-4089LOW
2.7
On affected Wago products an remote attacker with administrative privileges can access files to whic…Oct 17, 2023›
CVE-2016-9338LOW
2.7
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA,…Feb 13, 2017›
CVE-2006-2406LOW
2.6
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and…May 16, 2006›
CVE-2016-7960LOW
2.5
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files…Oct 13, 2016›
CVE-2016-5849LOW
2.5
Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by l…Jul 4, 2016›
CVE-2015-1015LOW
2.1
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 …Oct 6, 2015›
CVE-2015-0988LOW
2.1
Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project sourc…Oct 6, 2015›
CVE-2015-5084LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Andro…Aug 3, 2015›
CVE-2015-1602LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data wit…Apr 6, 2015›
CVE-2015-0999LOW
2.1
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2015-0996LOW
2.1
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2015-1599LOW
2.1
The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended…Mar 7, 2015›
CVE-2015-1598LOW
2.1
The Siemens SPCanywhere application for Android does not properly store application passwords, which…Mar 7, 2015›
CVE-2015-1355LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes i…Feb 18, 2015›
CVE-2014-5231LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5398LOW
2.1
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote atta…Aug 28, 2014›
CVE-2014-2381LOW
2.1
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encrypti…Aug 28, 2014›
CVE-2014-5233LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5232LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an inten…Jan 14, 2015›
CVE-2012-4693LOW
1.9
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algor…Dec 18, 2012›
CVE-2015-1009LOW
1.7
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition…Aug 1, 2015›