Vulnerabilities > Reliablecontrols > Mach Prowebcom Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-12-24 CVE-2019-18249 Cross-site Scripting vulnerability in Reliablecontrols Mach-Prowebcom Firmware and Mach-Prowebsys Firmware
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link.
4.3
2018-06-20 CVE-2018-12594 Information Exposure vulnerability in Reliablecontrols Mach-Prowebcom Firmware 7.80
Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct request for the data/fileinfo.xml or job/job.json file, as demonstrated the Master Password field.
network
low complexity
reliablecontrols CWE-200
5.0