Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Meg6260\-0410_firmware
(Schneider\-Electric)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 6 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-09-17 | CVE-2019-6835 | A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to inject client-side script when a user visits a web page. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 5.4 | ||
2019-09-17 | CVE-2019-6837 | A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 9.1 | ||
2019-09-17 | CVE-2019-6840 | A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 9.8 | ||
2019-09-17 | CVE-2019-6839 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to upload a rogue file. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 8.8 | ||
2019-09-17 | CVE-2019-6838 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to delete a critical file. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 6.5 | ||
2019-09-17 | CVE-2019-6836 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the file system to access the wrong file. | Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware | 7.5 |