Vulnerabilities
Vulnerable Software
Socomec:  Security Vulnerabilities
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
CVSS Score
5.7
EPSS Score
0.005
Published
2023-01-26
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.
CVSS Score
8.8
EPSS Score
0.011
Published
2021-12-15
An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes it possible to place a stored XSS payload. This is executed if an administrator views the System Event Log.
CVSS Score
5.4
EPSS Score
0.005
Published
2021-12-15
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
CVSS Score
9.8
EPSS Score
0.341
Published
2019-10-09


Contact Us

Shodan ® - All rights reserved