Recent CVEs
CVE-2024-7941
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
MEDIUM
Aug 27, 2024
CVE-2024-7940
The product exposes a service that is intended for local only to all network interfaces without any authentication.
HIGH
Aug 27, 2024
CVE-2024-3982
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
HIGH
Aug 27, 2024