ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-3073
Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote

Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.

NVD description · AI analysis pending
6.1<1%
  • weidmueller 19 iot md01 lan h4 s0011 firmware
  • weidmueller fp iot md01 4eu s2 00000 firmware
  • weidmueller fp iot md01 lan s2 00000 firmware
  • +1 more
CVE-2021-33533
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality.

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

NVD description · AI analysis pending
8.8
group max
2%
  • weidmueller ie-wl-bl-ap-cl-eu firmware
  • weidmueller ie-wlt-bl-ap-cl-eu firmware
  • weidmueller ie-wl-bl-ap-cl-us firmware
  • +1 more
CVE-2021-20999
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via externa

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

NVD description · AI analysis pending
9.8<1%
  • weidmueller uc20-wl2000-ac firmware
  • weidmueller uc20-wl2000-iot firmware
  • weidmueller iot-gw30 firmware
  • +1 more
CVE-2020-12525
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its proj

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

NVD description · AI analysis pending
7.81%
  • emerson rosemount transmitter interface software
  • emerson pactware
  • emerson dtminspector 3
  • +1 more
CVE-2019-16670
+4 in the same advisory: …16674 …16672 …16671 …16673
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices.

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.

NVD description · AI analysis pending
9.8
group max
2%
  • weidmueller ie-sw-pl09m-5gc-4gt firmware
  • weidmueller ie-sw-pl09mt-5gc-4gt firmware
  • weidmueller ie-sw-pl18m-2gc-16tx firmware
  • +1 more