CVE Vulnerability Database

Search and browse 124 known security vulnerabilities. Filter by severity, vendor, product, and year.

124 vulnerabilities found
CVE-2021-21974
8.8 high

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in

Vmware Cloud Foundation Feb 24, 2021
CVE-2021-22703
7.5 high

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP

Schneider-Electric Powerlogic Ion7400 Firmware Feb 19, 2021
CVE-2021-22702
7.5 high

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor i

Schneider-Electric Powerlogic Ion7400 Firmware Feb 19, 2021
CVE-2020-27279
7.5 high

A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).

Redlion Crimson Jan 6, 2021
CVE-2020-7566
7.3 high

A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-7565
7.3 high

A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.

Schneider-Electric Modicon M221 Firmware Nov 19, 2020
CVE-2020-28209
7.0 high

A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent s

Schneider-Electric Enterprise Server Installer Nov 19, 2020
CVE-2020-7564
8.8 high

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7563
8.8 high

A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-7562
8.1 high

A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file o

Schneider-Electric Modicon Tsxety4103 Firmware Nov 18, 2020
CVE-2020-15783
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on p

Siemens Sinumerik 840D Sl Firmware Nov 12, 2020
CVE-2020-17091
7.8 high

Microsoft Teams Remote Code Execution Vulnerability

Microsoft Teams Nov 11, 2020
CVE-2020-17003
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 3D Viewer Oct 16, 2020
CVE-2020-16918
7.8 high

<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulnerability by correcting how the Base3D ren

Microsoft 365 Apps Oct 16, 2020
CVE-2020-7488
7.5 high

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.

Schneider-Electric Ecostruxure Machine Expert Apr 22, 2020
CVE-2020-11725
7.8 high

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified "interesting side effects." NOTE: kernel engineers dispute this finding, because it could be relevant only if new callers w

Linux Linux Kernel Apr 12, 2020
CVE-2020-7477
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), wh

Schneider-Electric 140Noe77101 Firmware Mar 23, 2020
CVE-2020-6988
7.5 high

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix control

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2020-6984
7.5 high

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2019-18336
7.5 high

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions

Siemens Simatic S7-300 Cpu Firmware Mar 10, 2020
CVE-2020-6986
7.5 high

In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.

Omron Plc Cj1 Firmware Mar 5, 2020
CVE-2019-6857
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service of the controller when reading specific memory blocks using Mod

Schneider-Electric Modicon M580 Firmware Jan 6, 2020
CVE-2019-6856
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.

Schneider-Electric Modicon M580 Firmware Jan 6, 2020
CVE-2018-7794
7.5 high

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.

Schneider-Electric Modicon M580 Firmware Jan 6, 2020