CVE Vulnerabilities in 2013

11 documented vulnerabilities published in 2013.

Other years: 2026 2025 2024 2023 2022 2021 2020

Top Affected Vendors in 2013

All CVEs from 2013

CVE-2013-4734
7.3 high

dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtain non-administrative access via unspecified vectors.

Digital Alert Systems Dasdec Eas Jun 30, 2013
CVE-2013-4733
7.5 high

The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows remote attackers to obtain sensitive configuration and status information by reading log files.

Digital Alert Systems Dasdec Eas Jun 30, 2013
CVE-2013-1609
6.8 medium

Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.

Symantec Enterprise Vault For File System Archiving Mar 26, 2013
CVE-2013-2566
5.9 medium

The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

Oracle Communications Application Session Controller Mar 15, 2013
CVE-2010-5107
7.5 high

The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.

Openbsd Openssh Mar 7, 2013
CVE-2012-6442
7.5 high

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication w

Rockwellautomation Ethernet\/Ip Firmware Jan 24, 2013
CVE-2012-6440
4.8 medium

The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell A

Rockwellautomation Controllogix Controllers Jan 24, 2013
CVE-2012-6438
7.5 high

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could ca

Rockwellautomation Controllogix Controllers Jan 24, 2013
CVE-2012-6437
9.8 critical

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confide

Rockwellautomation Controllogix Controllers Jan 24, 2013
CVE-2012-6436
7.5 high

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successful exploitation of this vulnerability could ca

Rockwellautomation Controllogix Controllers Jan 24, 2013
CVE-2012-6435
7.5 high

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability

Rockwellautomation Controllogix Controllers Jan 24, 2013