Known Vulnerabilities for products from Secheron
Listed below are 7 of the newest known vulnerabilities associated with the vendor "Secheron".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-2105 json | Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including ... | 9.1 - CRITICAL | 2022-06-24 | 2022-07-06 |
| CVE-2022-2104 json | The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and ... | 9.8 - CRITICAL | 2022-06-24 | 2022-07-06 |
| CVE-2022-2103 json | An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive file... | 9.1 - CRITICAL | 2022-06-24 | 2022-07-05 |
| CVE-2022-2102 json | Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial f... | 7.5 - HIGH | 2022-06-24 | 2022-07-06 |
| CVE-2022-1668 json | Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for... | 9.8 - CRITICAL | 2022-06-24 | 2022-07-05 |
| CVE-2022-1667 json | Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser c... | 7.5 - HIGH | 2022-06-24 | 2022-07-05 |
| CVE-2022-1666 json | The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was use... | 6.5 - MEDIUM | 2022-06-24 | 2022-07-05 |