Vulnerabilities
Vulnerable Software
Azeotech:  >> Daqfactory  >> 16.3  Security Vulnerabilities
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
CVSS Score
7.8
EPSS Score
0.002
Published
2021-11-05
Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory.
CVSS Score
7.8
EPSS Score
0.001
Published
2021-11-05
The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
CVSS Score
5.7
EPSS Score
0.001
Published
2021-11-05
An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account.
CVSS Score
5.0
EPSS Score
0.001
Published
2021-11-05
An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.
CVSS Score
7.1
EPSS Score
0.001
Published
2017-09-09
An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path.
CVSS Score
5.3
EPSS Score
0.001
Published
2017-09-09


Contact Us

Shodan ® - All rights reserved