Show filters
113 Total Results
Displaying 11-20 of 113
Sort by:
Attacker Value
Unknown
CVE-2023-33413
Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2023-33412
Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
0
Attacker Value
Unknown
CVE-2023-33411
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
0
Attacker Value
Unknown
CVE-2023-34853
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
0
Attacker Value
Unknown
CVE-2023-35861
Disclosure Date: July 31, 2023 (last updated October 08, 2023)
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
0
Attacker Value
Unknown
CVE-2023-1800
Disclosure Date: April 02, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224768.
0
Attacker Value
Unknown
CVE-2021-38194
Disclosure Date: August 08, 2021 (last updated November 28, 2024)
An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.
0
Attacker Value
Unknown
CVE-2020-13858
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.
0
Attacker Value
Unknown
CVE-2020-15836
Disclosure Date: February 01, 2021 (last updated November 28, 2024)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The authentication function passes untrusted data to the operating system without proper sanitization. A crafted request can be sent to execute arbitrary commands as root.
0
Attacker Value
Unknown
CVE-2020-15834
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The wireless network password is exposed in a QR encoded picture that an unauthenticated adversary can download via the web-management interface.
0