CVE-2023-37482
- EPSS 0.05%
- Published 11.02.2025 11:15:11
- Last modified 11.02.2025 11:15:11
The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.
CVE-2024-46886
- EPSS 0.07%
- Published 08.10.2024 09:15:16
- Last modified 10.10.2024 12:56:30
The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate ...
CVE-2024-46887
- EPSS 0.12%
- Published 08.10.2024 09:15:16
- Last modified 08.04.2025 21:15:46
The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle t...
CVE-2022-30694
- EPSS 0.19%
- Published 08.11.2022 11:15:10
- Last modified 21.11.2024 07:03:11
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
CVE-2020-15782
- EPSS 0.41%
- Published 28.05.2021 16:15:07
- Last modified 21.11.2024 05:06:10
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS varia...
CVE-2019-10929
- EPSS 0.14%
- Published 13.08.2019 19:15:14
- Last modified 21.11.2024 04:20:10
A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V20....
- EPSS 0.41%
- Published 17.04.2019 14:29:03
- Last modified 21.11.2024 04:46:42
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vul...