Show filters
235 Total Results
Displaying 21-30 of 235
Sort by:
Attacker Value
Unknown
CVE-2024-21878
Disclosure Date: August 12, 2024 (last updated August 24, 2024)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.
0
Attacker Value
Unknown
CVE-2024-21877
Disclosure Date: August 12, 2024 (last updated August 24, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.
0
Attacker Value
Unknown
CVE-2024-21876
Disclosure Date: August 12, 2024 (last updated August 24, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.
0
Attacker Value
Unknown
CVE-2023-32471
Disclosure Date: July 24, 2024 (last updated September 12, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability to read contents of stack memory and use this information for further exploits.
0
Attacker Value
Unknown
CVE-2023-32466
Disclosure Date: July 24, 2024 (last updated September 12, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
0
Attacker Value
Unknown
CVE-2023-32472
Disclosure Date: July 10, 2024 (last updated September 11, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
0
Attacker Value
Unknown
CVE-2023-32467
Disclosure Date: July 10, 2024 (last updated September 11, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
0
Attacker Value
Unknown
CVE-2024-0158
Disclosure Date: July 02, 2024 (last updated August 01, 2024)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
0
Attacker Value
Unknown
CVE-2024-22429
Disclosure Date: May 17, 2024 (last updated January 31, 2025)
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-51059
Disclosure Date: January 16, 2024 (last updated January 23, 2024)
An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component of the administrative web interface.
0