| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). |
| An unauthenticated attacker can obtain other users' charger information. |
| An unauthenticated attacker can obtain EV charger energy consumption information of other users. |
| An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. |
| An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. |
| An unauthenticated attacker can hijack other users' devices and potentially control them. |
| Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. |
| Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. |
| An unauthenticated attacker can infer the existence of usernames in the system by querying an API. |
| An attacker can export other users' plant information. |
| An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. |
| Unauthenticated attackers can rename "rooms" of arbitrary users. |
| Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). |
| Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. |
| Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body including :team_name=team2 to bypass team scope check to gain access to certain resources belong to any other team. |
| Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. |
| An authenticated attacker can obtain any plant name by knowing the plant ID. |
| Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Filebird: from n/a through 6.4.2.1. |
| Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint. |
| Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint. |