Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2023-43743

Disclosure Date: December 08, 2023 (last updated December 14, 2023)
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.
Attacker Value
Unknown

CVE-2023-43742

Disclosure Date: December 08, 2023 (last updated December 14, 2023)
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation, the Zultys MX Administrator Windows client connects to port 7505 and attempts authentication, submitting the administrator username and password to the server. Upon authentication failure, the server sends a login failure message prompting the client to disconnect. However, if the client ignores the failure message instead and attempts to continue, the server does not forcibly close the connection and processes all subsequent requests from the client as if authentication had been successful.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2022-40137

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2021-0154

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-33123

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-33124

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-0156

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-0125

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.