Show filters
155 Total Results
Displaying 21-30 of 155
Sort by:
Attacker Value
Unknown

CVE-2023-6437

Disclosure Date: March 28, 2024 (last updated April 02, 2024)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command Injection.This issue affects TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3 : through 20240328. Also  the vulnerability continues in the TP-Link VX220-G2u and TP-Link VN020-G2u models due to the products not being produced and supported.
0
Attacker Value
Unknown

CVE-2024-25091

Disclosure Date: March 01, 2024 (last updated March 01, 2024)
Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in a specific file format (eml, dmg, vhd, iso, msi), malware may be taken outside the sandboxed environment.
0
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-38346

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.
Attacker Value
Unknown

CVE-2023-22356

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-36372

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-2993

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
Attacker Value
Unknown

CVE-2023-2992

Disclosure Date: June 26, 2023 (last updated September 16, 2024)
An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.