Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2016-8567 Use of Hard-coded Credentials vulnerability in Siemens Sicam Pas/Pqs 7.0
An issue was discovered in Siemens SICAM PAS before 8.00.
network
low complexity
siemens CWE-798
critical
9.8
2017-02-13 CVE-2016-8566 Credentials Management vulnerability in Siemens Sicam Pas/Pqs 7.0
An issue was discovered in Siemens SICAM PAS before 8.00.
local
low complexity
siemens CWE-255
7.8
2017-02-13 CVE-2016-8379 Unspecified vulnerability in Moxa products
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12.
network
high complexity
moxa
8.1
2017-02-13 CVE-2016-8378 Credentials Management vulnerability in Lynxspring Jenesys BAS Bridge 1.1.8
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older.
network
low complexity
lynxspring CWE-255
critical
9.8
2017-02-13 CVE-2016-8377 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fatek PLC Winproladder Firmware 3.11
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701.
network
low complexity
fatek CWE-119
8.0
2017-02-13 CVE-2016-8376 Open Redirect vulnerability in Kabona AB Webdatorcentral
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0.
network
high complexity
kabona-ab CWE-601
6.1
2017-02-13 CVE-2016-8374 Resource Exhaustion vulnerability in Schneider-Electric products
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe).
network
low complexity
schneider-electric CWE-400
7.5
2017-02-13 CVE-2016-8372 Credentials Management vulnerability in Moxa products
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12.
network
high complexity
moxa CWE-255
8.1
2017-02-13 CVE-2016-8370 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mitsubishielectric products
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions.
network
low complexity
mitsubishielectric CWE-327
7.5
2017-02-13 CVE-2016-8369 Cross-Site Request Forgery (CSRF) vulnerability in Lynxspring Jenesys BAS Bridge 1.1.8
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older.
network
low complexity
lynxspring CWE-352
8.8