Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2017-5153 Information Exposure Through Log Files vulnerability in Osisoft PI Coresight and PI web API
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit.
local
low complexity
osisoft CWE-532
7.8
2017-02-13 CVE-2017-5151 SQL Injection vulnerability in Panasonic Video Insight web Client 6.3.5.11
An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions.
network
low complexity
panasonic CWE-89
7.3
2017-02-13 CVE-2017-5146 Information Exposure vulnerability in Carlosgavazzi Vmu-C EM Firmware and Vmu-C PV Firmware
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17.
network
low complexity
carlosgavazzi CWE-200
7.5
2017-02-13 CVE-2017-5143 Path Traversal vulnerability in Honeywell XL web II Controller Xlwebexe10208/Xlwebexe20100
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior.
network
low complexity
honeywell CWE-22
8.6
2017-02-13 CVE-2016-9367 Resource Exhaustion vulnerability in Moxa products
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4.
network
low complexity
moxa CWE-400
7.5
2017-02-13 CVE-2016-9365 Cross-Site Request Forgery (CSRF) vulnerability in Moxa products
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4.
network
low complexity
moxa CWE-352
8.8
2017-02-13 CVE-2016-9364 Path Traversal vulnerability in Fidelex Fx-2030A-Basic Firmware and Fx-2030A Firmware
An issue was discovered in Fidelix FX-20 series controllers, versions prior to 11.50.19.
network
low complexity
fidelex CWE-22
7.5
2017-02-13 CVE-2016-9363 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Moxa products
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4.
network
low complexity
moxa CWE-119
7.3
2017-02-13 CVE-2016-9356 Improper Access Control vulnerability in Moxa Dacenter 1.4
An issue was discovered in Moxa DACenter Versions 1.4 and older.
local
low complexity
moxa CWE-284
7.8
2017-02-13 CVE-2016-9353 Permissions, Privileges, and Access Controls vulnerability in Advantech Susiaccess 3.0
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior.
local
low complexity
advantech CWE-264
7.8