Show filters
85 Total Results
Displaying 1-10 of 85
Sort by:
Attacker Value
Unknown

CVE-2024-5849

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
Attacker Value
Unknown

CVE-2024-38502

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
Attacker Value
Unknown

CVE-2024-38501

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
Attacker Value
Unknown

CVE-2024-31504

Disclosure Date: July 08, 2024 (last updated July 12, 2024)
Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.
Attacker Value
Unknown

CVE-2024-2052

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker modifies the URL to download to a different location.
0
Attacker Value
Unknown

CVE-2024-2051

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.
0
Attacker Value
Unknown

CVE-2024-2050

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the product.
0
Attacker Value
Unknown

CVE-2018-25090

Disclosure Date: March 13, 2024 (last updated January 05, 2025)
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
0
Attacker Value
Unknown

CVE-2015-10123

Disclosure Date: March 13, 2024 (last updated January 05, 2025)
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.
0
Attacker Value
Unknown

CVE-2023-34969

Disclosure Date: June 08, 2023 (last updated December 28, 2023)
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus, this is a denial-of-service vulnerability. The fixed versions are 1.12.28, 1.14.8, and 1.15.6.