Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2016-8368 Improper Synchronization vulnerability in Mitsubishielectric products
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions.
network
low complexity
mitsubishielectric CWE-662
8.6
2017-02-13 CVE-2016-8367 Resource Exhaustion vulnerability in Schneider-Electric products
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe).
network
low complexity
schneider-electric CWE-400
5.3
2017-02-13 CVE-2016-8364 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ibhsoftec S7-Softplc 4.12
An issue was discovered in IBHsoftec S7-SoftPLC prior to 4.12b.
network
low complexity
ibhsoftec CWE-119
critical
9.8
2017-02-13 CVE-2016-8363 Permissions, Privileges, and Access Controls vulnerability in Moxa products
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series.
network
low complexity
moxa CWE-264
critical
10.0
2017-02-13 CVE-2016-8362 Improper Authentication vulnerability in Moxa products
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series.
network
low complexity
moxa CWE-287
6.5
2017-02-13 CVE-2016-8361 Use of Hard-coded Credentials vulnerability in Lynxspring Jenesys BAS Bridge 1.1.8
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older.
network
low complexity
lynxspring CWE-798
8.6
2017-02-13 CVE-2016-8360 Double Free vulnerability in Moxa Softcms
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6.
network
high complexity
moxa CWE-415
8.1
2017-02-13 CVE-2016-8359 Cross-site Scripting vulnerability in Moxa products
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12.
network
low complexity
moxa CWE-79
6.1
2017-02-13 CVE-2016-8357 Permissions, Privileges, and Access Controls vulnerability in Lynxspring Jenesys BAS Bridge 1.1.8
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older.
network
low complexity
lynxspring CWE-264
7.1
2017-02-13 CVE-2016-8356 Cross-site Scripting vulnerability in Kabona AB Webdatorcentral
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0.
network
low complexity
kabona-ab CWE-79
8.2