- Synchronized data.

This commit is contained in:
CVE Team 2018-07-31 13:05:03 -04:00
parent fe63086f6b
commit 93dbe81f13
No known key found for this signature in database
GPG Key ID: 0DA1F9F56BC892E8
4 changed files with 21 additions and 4 deletions

View File

@ -65,7 +65,7 @@
"description_data" : [
{
"lang" : "eng",
"value" : "The affected controllers utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution."
"value" : "Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code execution."
}
]
},
@ -84,7 +84,14 @@
"references" : {
"reference_data" : [
{
"name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03",
"refsource" : "MISC",
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-151-03"
},
{
"name" : "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf",
"refsource" : "CONFIRM",
"url" : "https://web-material3.yokogawa.com/1/6712/details/YSAR-18-0004-E.pdf"
}
]
}

View File

@ -45,7 +45,7 @@
"description_data" : [
{
"lang" : "eng",
"value" : "Martem TELEM-GW6/GWM 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process."
"value" : "Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process."
}
]
},
@ -64,6 +64,8 @@
"references" : {
"reference_data" : [
{
"name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01",
"refsource" : "MISC",
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01"
}
]

View File

@ -45,7 +45,7 @@
"description_data" : [
{
"lang" : "eng",
"value" : "Martem TELEM-GW6/GWM 2018.04.18-linux_4-01-601cb47 and prior allows the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial process control channel."
"value" : "Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial process control channel."
}
]
},
@ -64,9 +64,13 @@
"references" : {
"reference_data" : [
{
"name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01",
"refsource" : "MISC",
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01"
},
{
"name" : "http://martem.eu/csa/Martem_CSA_Telem_1805184.pdf",
"refsource" : "CONFIRM",
"url" : "http://martem.eu/csa/Martem_CSA_Telem_1805184.pdf"
}
]

View File

@ -35,7 +35,7 @@
"description_data" : [
{
"lang" : "eng",
"value" : "Martem TELEM-GW6/GWM 2018.04.18-linux_4-01-601cb47 and prior allows improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code execution with target user privileges."
"value" : "Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code execution with target user privileges."
}
]
},
@ -54,9 +54,13 @@
"references" : {
"reference_data" : [
{
"name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01",
"refsource" : "MISC",
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-142-01"
},
{
"name" : "http://martem.eu/csa/Martem_CSA_Telem_1805181.pdf",
"refsource" : "CONFIRM",
"url" : "http://martem.eu/csa/Martem_CSA_Telem_1805181.pdf"
}
]