Show filters
70 Total Results
Displaying 21-30 of 70
Sort by:
Attacker Value
Unknown
CVE-2024-5948
Disclosure Date: June 13, 2024 (last updated August 08, 2024)
Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of multipart boundaries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23170.
0
Attacker Value
Unknown
CVE-2024-5947
Disclosure Date: June 13, 2024 (last updated August 08, 2024)
Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.
0
Attacker Value
Unknown
CVE-2024-4549
Disclosure Date: May 06, 2024 (last updated May 07, 2024)
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.
0
Attacker Value
Unknown
CVE-2024-4548
Disclosure Date: May 06, 2024 (last updated May 07, 2024)
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.
0
Attacker Value
Unknown
CVE-2024-4547
Disclosure Date: May 06, 2024 (last updated May 07, 2024)
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field
0
Attacker Value
Unknown
CVE-2024-4192
Disclosure Date: April 30, 2024 (last updated May 01, 2024)
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-3871
Disclosure Date: April 16, 2024 (last updated April 17, 2024)
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities.
Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices.
This issue affects DVW-W02W2-E2 through version 2.5.2.
0
Attacker Value
Unknown
CVE-2024-25574
Disclosure Date: April 01, 2024 (last updated April 02, 2024)
SQL injection vulnerability exists in GetDIAE_usListParameters.
0
Attacker Value
Unknown
CVE-2024-2863
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
0
Attacker Value
Unknown
CVE-2024-2862
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
0