Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2015-12-23 CVE-2015-7925 Cross-Site Request Forgery (CSRF) vulnerability in Ewon Firmware 10.0S0
Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware upload, removal of configuration data, or a reboot.
network
low complexity
ewon CWE-352
8.0
2015-12-23 CVE-2015-7924 Unspecified vulnerability in Ewon Firmware 10.0S0
eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
network
low complexity
ewon
8.8
2015-12-23 CVE-2015-7936 Cross-Site Request Forgery (CSRF) vulnerability in Motorola Moscad IP Gateway Firmware
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
network
low complexity
motorola CWE-352
7.5
2015-12-23 CVE-2015-7935 Information Exposure vulnerability in Motorola Moscad IP Gateway Firmware
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
motorola CWE-200
7.5
2015-12-23 CVE-2015-7917 Unspecified vulnerability in Opcsystems OPC Systems.Net 8.00.0023
Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
local
high complexity
opcsystems
7.2
2015-12-23 CVE-2015-7911 Credentials Management vulnerability in Saia Burgess Controls products
Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session.
network
low complexity
saia-burgess-controls CWE-255
critical
9.1
2015-12-23 CVE-2015-6851 Improper Access Control vulnerability in RSA Securid web Agent
EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.
local
high complexity
rsa CWE-284
6.7
2015-12-23 CVE-2015-6471 Information Exposure vulnerability in Eaton Proview
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.
network
low complexity
eaton CWE-200
5.3
2015-12-23 CVE-2015-6431 Resource Management Errors vulnerability in Cisco IOS XE 16.1.1
Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.
low complexity
cisco CWE-399
6.5
2015-12-22 CVE-2015-8373 Improper Input Validation vulnerability in ISC KEA 0.9.2/1.0.0
The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) via a malformed packet.
network
high complexity
isc CWE-20
6.8