Product:

Meg6501\-0002_firmware

(Schneider\-Electric)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 6
Date Id Summary Products Score Patch Annotated
2019-09-17 CVE-2019-6835 A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to inject client-side script when a user visits a web page. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 5.4
2019-09-17 CVE-2019-6837 A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 9.1
2019-09-17 CVE-2019-6840 A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 9.8
2019-09-17 CVE-2019-6839 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to upload a rogue file. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 8.8
2019-09-17 CVE-2019-6838 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to delete a critical file. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 6.5
2019-09-17 CVE-2019-6836 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the file system to access the wrong file. Meg6260\-0410_firmware, Meg6260\-0415_firmware, Meg6501\-0001_firmware, Meg6501\-0002_firmware 7.5