New vulnerability on the NVD: CVE-2020-12506

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication
This issue affects:
WAGO 750-362
version FW03 and prior versions.
WAGO 750-363
version FW03 and prior versions.
WAGO 750-823
version FW03 and prior versions.
WAGO 750-832/xxx-xxx
version FW03 and prior versions.
WAGO 750-862
version FW03 and prior versions.
WAGO 750-891
version FW03 and prior versions.
WAGO 750-890/xxx-xxx
version FW03 and prior versions.

Published at: September 30, 2020 at 12:15PM
View on website

New vulnerability on the NVD: CVE-2019-17098

Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials.
This issue affects:
August Connect Wi-Fi Bridge App
version v10.11.0 and prior versions on Android.
August Connect Firmware
version 2.2.12 and prior versions.

Published at: September 30, 2020 at 09:15AM
View on website

New vulnerability on the NVD: CVE-2018-6447

A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g could allow authenticated attackers with access to the web interface to hijack a user’s session and take over the account.

Published at: September 25, 2020 at 10:15AM
View on website

New vulnerability on the NVD: CVE-2018-6448

A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a remote attacker to perform a denial of service attack on the vulnerable host.

Published at: September 25, 2020 at 10:15AM
View on website

New vulnerability on the NVD: CVE-2018-6449

Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exploit this vulnerability by injecting arbitrary HTTP headers

Published at: September 25, 2020 at 10:15AM
View on website