CVE List

Id CVE No. Status Description Phase Votes Comments Actions
101965  CVE-2017-5145  Candidate  An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.  Assigned (20170103)  None (candidate not yet proposed)    View
101964  CVE-2017-5144  Candidate  An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication.  Assigned (20170103)  None (candidate not yet proposed)    View
101963  CVE-2017-5143  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.  Assigned (20170103)  None (candidate not yet proposed)    View
101962  CVE-2017-5142  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the parameters by accessing a specific URL because of Improper Privilege Management.  Assigned (20170103)  None (candidate not yet proposed)    View
101961  CVE-2017-5141  Candidate  An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION).  Assigned (20170103)  None (candidate not yet proposed)    View

Page 551 of 20943, showing 5 records out of 104715 total, starting on record 2751, ending on 2755

Actions