Vulnerabilities > Pepperl Fuchs

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-38501 Cross-site Scripting vulnerability in Pepperl-Fuchs products
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
network
low complexity
pepperl-fuchs CWE-79
6.1
2024-08-13 CVE-2024-38502 Cross-site Scripting vulnerability in Pepperl-Fuchs products
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
network
low complexity
pepperl-fuchs CWE-79
7.1
2024-08-13 CVE-2024-5849 Cross-site Scripting vulnerability in Pepperl-Fuchs products
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
network
low complexity
pepperl-fuchs CWE-79
7.1
2021-08-31 CVE-2021-33555 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
network
low complexity
pepperl-fuchs
7.5
2021-08-31 CVE-2021-34559 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.
network
low complexity
pepperl-fuchs
5.3
2021-08-31 CVE-2021-34561 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions.
network
low complexity
pepperl-fuchs
8.8
2021-08-31 CVE-2021-34562 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.
network
low complexity
pepperl-fuchs
6.1
2021-08-31 CVE-2021-34563 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie.
local
low complexity
pepperl-fuchs
3.3
2021-08-31 CVE-2021-34564 Unspecified vulnerability in Pepperl-Fuchs products
Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.
local
low complexity
pepperl-fuchs
5.5
2021-08-31 CVE-2021-34565 Unspecified vulnerability in Pepperl-Fuchs products
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
network
low complexity
pepperl-fuchs
critical
9.8