https://us-cert.cisa.gov/ics/advisories/icsa-20-196-03OUT-OF-BOUNDS READ CWE-125
By performing a flooding attack against the web server, an attacker might be able to gain read access to the device’s memory, and reveal confidential information.
MISSING AUTHENTICATION FOR CRITICAL FUNCTION CWE-306
An attacker with access to the device’s web server might be able to execute administrative commands without authentication.
MISSING ENCRYPTION OF SENSITIVE DATA CWE-311
An attacker in a privileged network position between a legitimate user and the web server might be able to conduct a man-in-the-middle attack and gain read and write access to the transmitted data.
USE OF PASSWORD HASH WITH INSUFFICIENT COMPUTATIONAL EFFORT CWE-916
An attacker with local access to the device might be able to retrieve passwords in clear text.
IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION (‘CROSS-SITE SCRIPTING) CWE-79
A stored cross-site-scripting (XSS) vulnerability is present in different locations of the web application. An attacker might be able to take over a session of a legitimate user.
BUFFER COPY WITHOUT CHECKING SIZE OF INPUT (‘CLASSIC BUFFER OVERFLOW’) CWE-120
A buffer overflow in various positions of the web application might enable an attacker with access to the web application to execute arbitrary code over the network.
IMPROPER NEUTRALIZATION OF SCRIPT-RELATED HTML TAGS IN A WEB PAGE (BASIC XSS) CWE-80
The web server could allow cross-site scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link.
MISSING AUTHENTICATION FOR A CRITICAL FUNCTION CWE-306
An attacker with access to the network could be able to install specially crafted firmware on the device.
AUTHENTICATION BYPASS BY CAPTURE-REPLAY CWE-294
An error in the challenge-response procedure could allow an attacker to replay authentication traffic and gain access to protected areas of the web application.
CVSS v3 9.8