Rapidscada
Rapidscada Rapid Scada: vulnerabilidades y CVE
Rapidscada Rapid Scada tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-47221 | Alta (7.5) | 0.35% | — | 22 sept 2024 | CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password. |
| CVE-2024-22096 | Media (6.5) | 0.59% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them to read arbitrary files from the system. |
| CVE-2024-22016 | Alta (7.8) | 0.16% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation. |
| CVE-2024-21869 | Media (5.5) | 0.16% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them. |
| CVE-2024-21866 | Media (5.3) | 0.41% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it receives a specific malformed request. |
| CVE-2024-21794 | Media (5.4) | 0.32% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page. |
| CVE-2024-21764 | Crítica (9.8) | 0.62% | — | 2 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port. |
| CVE-2024-21852 | Alta (8.8) | 1.2% | — | 1 feb 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution. |
| CVE-2022-44153 | Media (6.1) | 0.43% | — | 7 dic 2022 | Rapid Software LLC Rapid SCADA 5.8.4 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2020-22722 | Alta (7.8) | 0.46% | — | 14 ago 2020 | Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the… |
| CVE-2018-5313 | Alta (7.8) | 0.57% | — | 8 mar 2018 | A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists within the access control that is set and modified during the installation… |