[FD] St. Poelten UAS | Multiple Vulnerabilities in Phoenix Contact TC Cloud Client / TC Router / Cloud Client

2023-08-11 Thread Weber Thomas via Fulldisclosure
St. Pölten UAS --- title| Multiple Vulnerabilities product| Phoenix Contact TC Cloud Client 1002-4G*, | TC Router 3002T-4G, Cloud Client 1101T-TX/TX vulnerable version| <2.0

[FD] St. Poelten UAS | Multiple XSS in Advantech EKI 15XX Series

2023-08-11 Thread Weber Thomas via Fulldisclosure
St. Pölten UAS --- title| Multiple XSS in Advantech product| Advantech EKI-1524-CE series, EKI-1522 series, | EKI-1521 series vulnerable version| <=1.21 (CVE-2023-4202), <=1

[FD] Qualys mis-uses ssh, fails to scan and protect, facilitates internal attack

2023-08-11 Thread Paul Szabo via Fulldisclosure
=== Introduction === My institution uses Qualys www.qualys.com to scan for vulnerabilities, including on some Debian Linux machines that I manage. The scanner does some network scans, and also logs in to each machine to do "authenticated scans".