Show filters
329,363 Total Results
Displaying 2,531-2,540 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-28808

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.
0
Attacker Value
Unknown

CVE-2024-28807

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.
0
Attacker Value
Unknown

CVE-2024-28813

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.
0
Attacker Value
Unknown

CVE-2024-28812

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.
0
Attacker Value
Unknown

CVE-2024-28811

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
0
Attacker Value
Unknown

CVE-2024-28810

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.
0
Attacker Value
Unknown

CVE-2024-46635

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.
0
Attacker Value
Unknown

CVE-2024-46511

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code via the LogicLoadEc2DeployLambda and CredsGenFunction function.
0
Attacker Value
Unknown

CVE-2024-42017

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint hosting the application, without any authentication.
0
Attacker Value
Unknown

CVE-2024-35495

Disclosure Date: September 30, 2024 (last updated October 01, 2024)
An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic.
0