Show filters
250 Total Results
Displaying 31-40 of 250
Sort by:
Attacker Value
Unknown

CVE-2022-45140

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
Attacker Value
Unknown

CVE-2022-45139

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a limited amount of information readable the impact only affects a small subset of confidentiality.
Attacker Value
Unknown

CVE-2022-45138

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full compromise of the device.
Attacker Value
Unknown

CVE-2022-45137

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that targets the users browser. This leads to a limited impact of confidentiality and integrity but no impact of availability.
Attacker Value
Unknown

CVE-2022-3738

Disclosure Date: January 19, 2023 (last updated February 24, 2025)
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
Attacker Value
Unknown

CVE-2022-33916

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
Attacker Value
Unknown

CVE-2022-30944

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-30601

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.
Attacker Value
Unknown

CVE-2022-28697

Disclosure Date: August 18, 2022 (last updated November 29, 2024)
Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Attacker Value
Unknown

CVE-2022-36447

Disclosure Date: July 29, 2022 (last updated October 08, 2023)
An inflation issue was discovered in Chia Network CAT1 Standard 1.0.0. Previously minted tokens minted on the Chia blockchain using the CAT1 standard can be inflated to an arbitrary extent by any holder of any amount of the token. The total amount of the token can be increased as high as the malicious actor pleases. This is true for every CAT1 on the Chia blockchain regardless of issuance rules. This attack is auditable on chain, so maliciously altered coins can potentially be marked by off-chain observers as malicious.