NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28321 | CVE-2015-7925 | Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware upload, removal of configuration data, or a reboot. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 28320 | CVE-2015-7924 | eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 28319 | CVE-2015-7923 | Westermo WeOS before 4.19.0 uses the same SSL private key across different customers" installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key. | 2 | 9.3 | High | 2017-01-19 | 2016-03-07 | View | |
| 83579 | CVE-2015-7922 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2015. Notes: none. | 1 | 2017-03-18 | 2017-03-16 | View | |||
| 28318 | CVE-2015-7921 | The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials. | 2 | 6.4 | Medium | 2017-01-19 | 2016-04-07 | View |
Page 2680 of 17672, showing 5 records out of 88360 total, starting on record 13396, ending on 13400