Vulnerabilities > Reliablecontrols

DATE CVE VULNERABILITY TITLE RISK
2019-12-24 CVE-2019-18249 Cross-site Scripting vulnerability in Reliablecontrols Mach-Prowebcom Firmware and Mach-Prowebsys Firmware
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link.
network
low complexity
reliablecontrols CWE-79
6.1
2019-12-11 CVE-2019-18245 Unquoted Search Path or Element vulnerability in Reliablecontrols Rc-Licensemanager 3.4
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.
local
low complexity
reliablecontrols CWE-428
7.8
2018-06-20 CVE-2018-12594 Information Exposure vulnerability in Reliablecontrols Mach-Prowebcom Firmware 7.80
Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Password field.
network
low complexity
reliablecontrols CWE-200
7.5