CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104394 | CVE-2017-7574 | Candidate | Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104395 | CVE-2017-7575 | Candidate | Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a x00x01x00x00x00x05x01x5ax00x03x00 request to the Modbus port (502/tcp). Subsequently the application may be arbitrarily downloaded, modified, and uploaded. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104396 | CVE-2017-7576 | Candidate | DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104397 | CVE-2017-7577 | Candidate | XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. | Assigned (20170406) | None (candidate not yet proposed) | View | |
86296 | CVE-2015-9019 | Candidate | In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs. | Assigned (20170405) | None (candidate not yet proposed) | View |
Page 649 of 20943, showing 5 records out of 104715 total, starting on record 3241, ending on 3245