<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_cisa/10</id>
  <title>Most recent entries from csaf_cisa</title>
  <updated>2026-10-03T01:32:52.366090+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-012-01</id>
    <title>ICSA-17-012-01 — Advantech WebAccess</title>
    <updated>2017-01-12T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.CVE-2017-5154 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted.CVE-2017-5152 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-012-01"/>
    <published>2017-01-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-012-02</id>
    <title>ICSA-17-012-02 — VideoInsight Web Client</title>
    <updated>2017-01-12T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A SQL Injection vulnerability has been identified, which may allow remote code execution.CVE-2017-5151 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-012-02"/>
    <published>2017-01-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-012-03</id>
    <title>ICSA-17-012-03 — Carlo Gavazzi VMU-C EM and VMU-C PV</title>
    <updated>2017-01-12T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The access control flaw allows access to most application functions without authentication.CVE-2017-5144 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Successful exploitation of this vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5145 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Sensitive information stored in clear-text.CVE-2017-5146 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-012-03"/>
    <published>2017-01-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-017-01</id>
    <title>ICSA-17-017-01 — PHOENIX CONTACT mGuard</title>
    <updated>2017-01-17T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.CVE-2017-5159 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-017-01"/>
    <published>2017-01-17T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-024-01</id>
    <title>ICSA-17-024-01 — Schneider Electric Wonderware Historian</title>
    <updated>2017-01-24T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.CVE-2017-5155 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-024-01"/>
    <published>2017-01-24T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-026-01</id>
    <title>ICSA-17-026-01 — Eaton ePDU Path Traversal Vulnerability</title>
    <updated>2017-01-26T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated attacker may be able to access configuration files with a specially crafted URL. CVE-2016-9357 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-026-01"/>
    <published>2017-01-26T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-031-02</id>
    <title>ICSA-17-031-02 — Ecava IntegraXor</title>
    <updated>2017-01-31T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host 's database could be subject to read, write, and delete commands.CVE-2016-8341 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-031-02"/>
    <published>2017-01-31T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-033-01</id>
    <title>ICSA-17-033-01 — Honeywell XL Web II Controller Vulnerabilities</title>
    <updated>2017-02-02T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions. CVE-2017-5141 has been assigned to this vulnerability. A CVSS v3 base score of 6.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L). Any user is able to disclose a password by accessing a specif…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-033-01"/>
    <published>2017-02-02T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-17-009-01a</id>
    <title>ICSMA-17-009-01A — ICSMA-17-009-01A_St. Jude Merlin@home Transmitter Vulnerability (Update A)</title>
    <updated>2017-02-06T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical's web site, Merlin.net, are not verified. This may allow a remote attacker to access or influence communications between the identified endpoints. CVE-2017-5149 has been assigned to this vulnerability. A CVSS v3 base score of 8.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-17-009-01a"/>
    <published>2017-01-09T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-17-031-01a</id>
    <title>ICSA-17-031-01A — BINOM3 Electric Power Quality Meter (Update A)</title>
    <updated>2017-02-07T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user 's browser session.CVE-2017-5164 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). Lack of authentication for remote service gives access to application set up and configuration.CVE-2017-5162 has been assigned to this vulnerability. A CVSS v3 base score of 10 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5165 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). This flaw can be used to gain privileged access to the device.CVE-2017-5166 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Users do not have any option to change their own passwords.CVE-2017-5167 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-17-031-01a"/>
    <published>2017-01-31T00:00:00+00:00</published>
  </entry>
</feed>
