Show filters
794 Total Results
Displaying 121-130 of 794
Sort by:
Attacker Value
Unknown
CVE-2023-46388
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.
0
Attacker Value
Unknown
CVE-2023-46387
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.
0
Attacker Value
Unknown
CVE-2023-46386
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.
0
Attacker Value
Unknown
CVE-2023-46385
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.
0
Attacker Value
Unknown
CVE-2023-46384
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.
0
Attacker Value
Unknown
CVE-2023-46383
Disclosure Date: November 30, 2023 (last updated September 20, 2024)
LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.
0
Attacker Value
Unknown
CVE-2023-6263
Disclosure Date: November 22, 2023 (last updated December 18, 2023)
An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.
0
Attacker Value
Unknown
CVE-2023-32701
Disclosure Date: November 14, 2023 (last updated November 22, 2023)
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition.
0
Attacker Value
Unknown
CVE-2023-23583
Disclosure Date: November 14, 2023 (last updated November 29, 2023)
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2023-22327
Disclosure Date: November 14, 2023 (last updated November 28, 2023)
Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.
0