xylem kayıtları
xylem üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-23 Relative Path Traversal1
- CWE-256 Plaintext Storage of a Password1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-427 Uncontrolled Search Path Element1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-25176İstismar yok | Rockwell Automation ISaGRAF5 Runtime Relative Path Traversalschneider-electric · easergy t300 firmware · CWE-23 | Kritik9,8 | — | %6,4 | 18 Mar 2022 |
40Planlayın | CVE-2021-41063İstismar yok | SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackexylem · aanderaa geoview · CWE-89 | Kritik9,8 | — | %2,0 | 8 Ara 2021 |
36İzleyin | CVE-2020-25178İstismar yok | Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Informationschneider-electric · easergy t300 firmware · CWE-319 | Yüksek8,8 | — | %1,7 | 18 Mar 2022 |
35İzleyin | CVE-2021-42833İstismar yok | Use of hardcoded credentials impacting AquaView versions 1.60, 7.x, 8.xxylem · aquaview · CWE-798 | Yüksek8,8 | — | %0,2 | 7 Şub 2022 |
26İzleyin | CVE-2020-25180İstismar yok | Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Keyschneider-electric · easergy t300 firmware · CWE-321 | Orta6,5 | — | %1,2 | 18 Mar 2022 |
26İzleyin | CVE-2020-25182İstismar yok | Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Elementschneider-electric · easergy t300 firmware · CWE-427 | Orta6,7 | — | %0,4 | 18 Mar 2022 |
22İzleyin | CVE-2020-25184İstismar yok | Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentialsschneider-electric · easergy t300 firmware · CWE-256 | Orta5,5 | — | %0,4 | 18 Mar 2022 |
- CVE-2020-2517641Planlayın
Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal
KritikCVSS 9,8İstismar yokEPSS %6schneider-electric · easergy t300 firmware18 Mar 2022
- CVE-2021-4106340Planlayın
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attacke
KritikCVSS 9,8İstismar yokEPSS %2xylem · aanderaa geoview8 Ara 2021
- CVE-2020-2517836İzleyin
Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Information
YüksekCVSS 8,8İstismar yokEPSS %2schneider-electric · easergy t300 firmware18 Mar 2022
- CVE-2021-4283335İzleyin
Use of hardcoded credentials impacting AquaView versions 1.60, 7.x, 8.x
YüksekCVSS 8,8İstismar yokEPSS %0xylem · aquaview7 Şub 2022
- CVE-2020-2518026İzleyin
Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Key
OrtaCVSS 6,5İstismar yokEPSS %1schneider-electric · easergy t300 firmware18 Mar 2022
- CVE-2020-2518226İzleyin
Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element
OrtaCVSS 6,7İstismar yokEPSS %0schneider-electric · easergy t300 firmware18 Mar 2022
- CVE-2020-2518422İzleyin
Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentials
OrtaCVSS 5,5İstismar yokEPSS %0schneider-electric · easergy t300 firmware18 Mar 2022