Show filters
65 Total Results
Displaying 11-20 of 65
Sort by:
Attacker Value
Unknown

CVE-2024-7467

Disclosure Date: August 05, 2024 (last updated February 26, 2025)
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function sslvpn_config_mod of the file /vpn/list_ip_network.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273560. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-7120

Disclosure Date: July 26, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.
Attacker Value
Unknown

CVE-2024-1969

Disclosure Date: April 29, 2024 (last updated February 26, 2025)
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateManager: from 9.7 before 11.2.624095033.
0
Attacker Value
Unknown

CVE-2024-1579

Disclosure Date: April 29, 2024 (last updated February 26, 2025)
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager: before 11.2.624071020.
0
Attacker Value
Unknown

CVE-2023-3675

Disclosure Date: April 18, 2024 (last updated February 26, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web GUI) allows Reading Data from System Resources.This issue affects GateManager: from 11.0.623074018 before 11.0.623373051.
0
Attacker Value
Unknown

CVE-2023-2912

Disclosure Date: July 17, 2023 (last updated February 25, 2025)
Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.
Attacker Value
Unknown

CVE-2023-0317

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.
Attacker Value
Unknown

CVE-2022-4308

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.
Attacker Value
Unknown

CVE-2022-38125

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.
Attacker Value
Unknown

CVE-2022-38124

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.