Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2018
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-07-24
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.
CVSS Score
7.5
EPSS Score
0.004
Published
2018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.
CVSS Score
9.8
EPSS Score
0.002
Published
2018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.
CVSS Score
9.8
EPSS Score
0.002
Published
2018-07-24
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-07-24
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-07-24
xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-07-24
An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-07-24
An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4_Stz2Atom class.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-07-24
An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-07-24


Contact Us

Shodan ® - All rights reserved