Show filters
133 Total Results
Displaying 11-20 of 133
Sort by:
Attacker Value
Unknown

CVE-2023-28865

Disclosure Date: August 08, 2024 (last updated August 20, 2024)
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Attacker Value
Unknown

CVE-2023-24064

Disclosure Date: August 08, 2024 (last updated August 20, 2024)
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Attacker Value
Unknown

CVE-2023-24063

Disclosure Date: August 08, 2024 (last updated August 20, 2024)
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Attacker Value
Unknown

CVE-2023-24062

Disclosure Date: August 08, 2024 (last updated August 20, 2024)
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Attacker Value
Unknown

CVE-2024-25023

Disclosure Date: July 10, 2024 (last updated September 21, 2024)
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
Attacker Value
Unknown

CVE-2022-38383

Disclosure Date: June 28, 2024 (last updated August 02, 2024)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.
Attacker Value
Unknown

CVE-2023-47726

Disclosure Date: June 18, 2024 (last updated June 19, 2024)
IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 272087.
0
Attacker Value
Unknown

CVE-2023-47727

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.
0
Attacker Value
Unknown

CVE-2022-38386

Disclosure Date: May 01, 2024 (last updated May 02, 2024)
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.
0
Attacker Value
Unknown

CVE-2024-3911

Disclosure Date: April 23, 2024 (last updated January 05, 2025)
An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of rendered UI layers or frames. 
0