Show filters
941 Total Results
Displaying 141-150 of 941
Sort by:
Attacker Value
Unknown
CVE-2023-29412
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command
Injection') vulnerability exists that could cause remote code execution when manipulating
internal methods through Java RMI interface.
0
Attacker Value
Unknown
CVE-2023-29411
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
0
Attacker Value
Unknown
CVE-2023-28003
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to
maintain unauthorized access over a hijacked session in PME after the legitimate user has
signed out of their account.
0
Attacker Value
Unknown
CVE-2023-25555
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability exists that could allow a user that knows the credentials to
execute unprivileged shell commands on the appliance over SSH.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25554
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability exists that allows a local privilege escalation on the appliance
when a maliciously crafted Operating System command is entered on the device.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25553
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the
webserver.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25552
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized
content, changes or deleting of content, or performing unauthorized functions when tampering
the Device File Transfer settings on DCE endpoints.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25551
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters
over HTTP.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25550
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
allows remote code execution via the “hostname” parameter when maliciously crafted hostname
syntax is entered.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0
Attacker Value
Unknown
CVE-2023-25549
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
allows for remote code execution when using a parameter of the DCE network settings
endpoint.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
0