SOCOMEC
CVE Severity Distribution (All Time)
Timeline Overview
Recent CVEs
An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perfo…
Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users in…
A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploadin…
Persistent cross-site scripting (XSS) in the web application of MOD3GP-SY-120K allows an authenticated remote attacker to introduce arbitrar…
Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers …
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information…
The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject m…
Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions…
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentica…
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors…