Логотип exploitDog
bind:CVE-2023-2072
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2072

Количество 3

Количество 3

nvd логотип

CVE-2023-2072

больше 2 лет назад

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-c69m-37cm-p3p7

больше 2 лет назад

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-04306

больше 2 лет назад

Уязвимость монитора для распределения электрической нагрузки Rockwell Automation PowerMonitor 1000, связанная с недостатками проверки вводимых пользователем данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-2072

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-c69m-37cm-p3p7

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-04306

Уязвимость монитора для распределения электрической нагрузки Rockwell Automation PowerMonitor 1000, связанная с недостатками проверки вводимых пользователем данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу