Show filters
111 Total Results
Displaying 21-30 of 111
Sort by:
Attacker Value
Unknown
CVE-2023-0053
Disclosure Date: March 02, 2023 (last updated October 27, 2023)
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and
prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet
available for device management. Any sensitive information communicated
through these protocols, such as credentials, is sent in cleartext. An
attacker could obtain sensitive information such as user credentials to
gain access to the system.
0
Attacker Value
Unknown
CVE-2023-0776
Disclosure Date: February 11, 2023 (last updated November 08, 2023)
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce.
0
Attacker Value
Unknown
CVE-2022-47951
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
0
Attacker Value
Unknown
CVE-2023-0052
Disclosure Date: January 20, 2023 (last updated October 27, 2023)
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.
0
Attacker Value
Unknown
CVE-2015-10006
Disclosure Date: January 01, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of the patch is 9d18a39944d79dfedacd754a742df38f99d3c0e2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217172.
0
Attacker Value
Unknown
CVE-2022-41870
Disclosure Date: September 30, 2022 (last updated October 08, 2023)
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
0
Attacker Value
Unknown
CVE-2022-37394
Disclosure Date: August 03, 2022 (last updated October 08, 2023)
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail to restart, resulting in a possible denial of service. Only Nova deployments configured with SR-IOV are affected.
0
Attacker Value
Unknown
CVE-2021-38289
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and other unspecified impacts.
0
Attacker Value
Unknown
CVE-2022-24693
Disclosure Date: March 30, 2022 (last updated October 07, 2023)
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
0
Attacker Value
Unknown
CVE-2022-27658
Disclosure Date: March 28, 2022 (last updated October 07, 2023)
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
0