VYPR

Iiot Monitor

by Schneider Electric

CVEs (4)

  • CVE-2018-7836CriDec 24, 2018
    risk 0.66cvss 9.8epss 0.32

    An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

  • CVE-2018-7837HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.01

    An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect…

  • CVE-2018-7835HigDec 24, 2018
    risk 0.49cvss 7.5epss 0.02

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow access to files available to SYSTEM user.

  • CVE-2018-7839MedFeb 6, 2019
    risk 0.36cvss 5.5epss 0.00

    A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.