Show filters
380 Total Results
Displaying 31-40 of 380
Sort by:
Attacker Value
Unknown
CVE-2023-20216
Disclosure Date: August 03, 2023 (last updated January 25, 2024)
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system.
This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions.
There are workarounds that address this vulnerability.
0
Attacker Value
Unknown
CVE-2023-20210
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.
The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
0
Attacker Value
Unknown
CVE-2022-40137
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-28815
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.
0
Attacker Value
Unknown
CVE-2022-28814
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.
0
Attacker Value
Unknown
CVE-2022-28812
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.
0
Attacker Value
Unknown
CVE-2022-22526
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.
0
Attacker Value
Unknown
CVE-2022-22525
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function
0
Attacker Value
Unknown
CVE-2022-22523
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.
0
Attacker Value
Unknown
CVE-2022-22522
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.
0