Show filters
296 Total Results
Displaying 21-30 of 296
Sort by:
Attacker Value
Unknown

CVE-2024-0387

Disclosure Date: February 26, 2024 (last updated October 28, 2024)
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
0
Attacker Value
Unknown

CVE-2023-6094

Disclosure Date: December 31, 2023 (last updated January 10, 2024)
A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of attack could be executed to gather sensitive information or to facilitate a subsequent attack against the target.
Attacker Value
Unknown

CVE-2023-6093

Disclosure Date: December 31, 2023 (last updated January 09, 2024)
A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application.
Attacker Value
Unknown

CVE-2023-5962

Disclosure Date: December 23, 2023 (last updated October 28, 2024)
A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization.
Attacker Value
Unknown

CVE-2023-5961

Disclosure Date: December 23, 2023 (last updated December 29, 2023)
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.
Attacker Value
Unknown

CVE-2023-5035

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for sensitive cookies in HTTPS sessions is not set, which could cause the cookie to be transmitted in plaintext over an HTTP session. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.
Attacker Value
Unknown

CVE-2023-4217

Disclosure Date: November 02, 2023 (last updated November 10, 2023)
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.
Attacker Value
Unknown

CVE-2023-5627

Disclosure Date: November 01, 2023 (last updated November 10, 2023)
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service.
Attacker Value
Unknown

CVE-2023-4452

Disclosure Date: November 01, 2023 (last updated November 10, 2023)
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
Attacker Value
Unknown

CVE-2023-4929

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.