Show filters
1,987 Total Results
Displaying 111-120 of 1,987
Sort by:
Attacker Value
Unknown
CVE-2024-8279
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
0
Attacker Value
Unknown
CVE-2024-8278
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
0
Attacker Value
Unknown
CVE-2024-8059
Disclosure Date: September 13, 2024 (last updated September 14, 2024)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
0
Attacker Value
Unknown
CVE-2024-45105
Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-8533
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
0
Attacker Value
Unknown
CVE-2024-38222
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
0
Attacker Value
Unknown
CVE-2024-45032
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system.
0
Attacker Value
Unknown
CVE-2024-7654
Disclosure Date: September 03, 2024 (last updated September 06, 2024)
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that could spoof or deceive web interface users. Unauthorized use of the OEE/OEM discovery service was remediated by deactivating the discovery service by default.
0
Attacker Value
Unknown
CVE-2024-7346
Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full TLS certificate validation is needed for network security. The existing certificates should be replaced with CA-signed certificates from a recognized certificate authority that contain the necessary information to support host name validation.
0
Attacker Value
Unknown
CVE-2024-7345
Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all supported release platforms
0