ls-electric kayıtları
ls-electric üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-306 Missing Authentication for Critical Function3
- CWE-284 Improper Access Control2
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-788 Access of Memory Location After End of Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-22804İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC.ls-electric · xbc-dn32u firmware · CWE-306 | Kritik9,8 | — | %0,7 | 15 Şub 2023 |
39İzleyin | CVE-2023-22807İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol.ls-electric · xbc-dn32u firmware · CWE-284 | Kritik9,8 | — | %0,7 | 15 Şub 2023 |
36İzleyin | CVE-2023-0102İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command.ls-electric · xbc-dn32u firmware · CWE-306 | Kritik9,1 | — | %0,7 | 15 Şub 2023 |
30İzleyin | CVE-2023-0103İstismar yok | If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communicls-electric · xbc-dn32u firmware · CWE-788 | Yüksek7,5 | — | %0,7 | 15 Şub 2023 |
30İzleyin | CVE-2023-22803İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC.ls-electric · xbc-dn32u firmware · CWE-306 | Yüksek7,5 | — | %0,6 | 15 Şub 2023 |
30İzleyin | CVE-2023-22806İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protols-electric · xbc-dn32u firmware · CWE-319 | Yüksek7,5 | — | %0,4 | 15 Şub 2023 |
23İzleyin | CVE-2022-2758İstismar yok | Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co.ls-electric · xg5000 · CWE-326 | Orta5,9 | — | %0,4 | 31 Ağu 2022 |
17İzleyin | CVE-2023-22805İstismar yok | LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature.ls-electric · xbc-dn32u firmware · CWE-284 | Orta4,3 | — | %0,7 | 15 Şub 2023 |
- CVE-2023-2280439İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC.
KritikCVSS 9,8İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2023-2280739İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol.
KritikCVSS 9,8İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2023-010236İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command.
KritikCVSS 9,1İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2023-010330İzleyin
If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communic
YüksekCVSS 7,5İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2023-2280330İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC.
YüksekCVSS 7,5İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2023-2280630İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT proto
YüksekCVSS 7,5İstismar yokEPSS %0ls-electric · xbc-dn32u firmware15 Şub 2023
- CVE-2022-275823İzleyin
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co.
OrtaCVSS 5,9İstismar yokEPSS %0ls-electric · xg500031 Ağu 2022
- CVE-2023-2280517İzleyin
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature.
OrtaCVSS 4,3İstismar yokEPSS %1ls-electric · xbc-dn32u firmware15 Şub 2023