<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_cisa</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:22:06 +0000</lastBuildDate>
    <item>
      <title>ICSA-17-012-01 — Advantech WebAccess</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-012-01</link>
      <description>&lt;p&gt;To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.CVE-2017-5154 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted.CVE-2017-5152 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.CVE-2017-5154 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted.CVE-2017-5152 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-012-01</guid>
      <pubDate>Thu, 12 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-012-02 — VideoInsight Web Client</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-012-02</link>
      <description>&lt;p&gt;A SQL Injection vulnerability has been identified, which may allow remote code execution.CVE-2017-5151 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A SQL Injection vulnerability has been identified, which may allow remote code execution.CVE-2017-5151 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-012-02</guid>
      <pubDate>Thu, 12 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-012-03 — Carlo Gavazzi VMU-C EM and VMU-C PV</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-012-03</link>
      <description>&lt;p&gt;The access control flaw allows access to most application functions without authentication.CVE-2017-5144 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Successful exploitation of this vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5145 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Sensitive information stored in clear-text.CVE-2017-5146 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The access control flaw allows access to most application functions without authentication.CVE-2017-5144 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Successful exploitation of this vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5145 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Sensitive information stored in clear-text.CVE-2017-5146 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-012-03</guid>
      <pubDate>Thu, 12 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-017-01 — PHOENIX CONTACT mGuard</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-017-01</link>
      <description>&lt;p&gt;When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.CVE-2017-5159 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When updating an mGuard device to Version 8.4.0 via the update-upload facility, the update will succeed, but it will reset the password of the admin user to its default value.CVE-2017-5159 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-017-01</guid>
      <pubDate>Tue, 17 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-024-01 — Schneider Electric Wonderware Historian</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-024-01</link>
      <description>&lt;p&gt;Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.CVE-2017-5155 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.CVE-2017-5155 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-024-01</guid>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-026-01 — Eaton ePDU Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-026-01</link>
      <description>&lt;p&gt;An unauthenticated attacker may be able to access configuration files with a specially crafted URL. CVE-2016-9357 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker may be able to access configuration files with a specially crafted URL. CVE-2016-9357 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-026-01</guid>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-031-02 — Ecava IntegraXor</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-031-02</link>
      <description>&lt;p&gt;The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host &amp;#39;s database could be subject to read, write, and delete commands.CVE-2016-8341 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host &amp;#39;s database could be subject to read, write, and delete commands.CVE-2016-8341 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-031-02</guid>
      <pubDate>Tue, 31 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-033-01 — Honeywell XL Web II Controller Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-033-01</link>
      <description>&lt;p&gt;Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions. CVE-2017-5141 has been assigned to this vulnerability. A CVSS v3 base score of 6.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L). Any user is able to disclose a password by accessing a specif…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Any user is able to disclose a password by accessing a specific URL. CVE-2017-5139 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Password is stored in clear text. CVE-2017-5140 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions. CVE-2017-5141 has been assigned to this vulnerability. A CVSS v3 base score of 6.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L). Any user is able to disclose a password by accessing a specif…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-033-01</guid>
      <pubDate>Thu, 02 Feb 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSMA-17-009-01A — ICSMA-17-009-01A_St. Jude Merlin@home Transmitter Vulnerability (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-17-009-01a</link>
      <description>&lt;p&gt;The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical&amp;#39;s web site, Merlin.net, are not verified. This may allow a remote attacker to access or influence communications between the identified endpoints. CVE-2017-5149 has been assigned to this vulnerability. A CVSS v3 base score of 8.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The identities of the endpoints for the communication channel between the transmitter and St. Jude Medical&amp;#39;s web site, Merlin.net, are not verified. This may allow a remote attacker to access or influence communications between the identified endpoints. CVE-2017-5149 has been assigned to this vulnerability. A CVSS v3 base score of 8.9 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-17-009-01a</guid>
      <pubDate>Mon, 09 Jan 2017 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ICSA-17-031-01A — BINOM3 Electric Power Quality Meter (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-17-031-01a</link>
      <description>&lt;p&gt;Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user &amp;#39;s browser session.CVE-2017-5164 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). Lack of authentication for remote service gives access to application set up and configuration.CVE-2017-5162 has been assigned to this vulnerability. A CVSS v3 base score of 10 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5165 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). This flaw can be used to gain privileged access to the device.CVE-2017-5166 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Users do not have any option to change their own passwords.CVE-2017-5167 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Input sent from a malicious client is not properly verified by the server. An attacker can execute arbitrary script code in another user &amp;#39;s browser session.CVE-2017-5164 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). Lack of authentication for remote service gives access to application set up and configuration.CVE-2017-5162 has been assigned to this vulnerability. A CVSS v3 base score of 10 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.CVE-2017-5165 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). This flaw can be used to gain privileged access to the device.CVE-2017-5166 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Users do not have any option to change their own passwords.CVE-2017-5167 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-17-031-01a</guid>
      <pubDate>Tue, 31 Jan 2017 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
