Show filters
796 Total Results
Displaying 41-50 of 796
Sort by:
Attacker Value
Unknown

CVE-2024-5680

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Attacker Value
Unknown

CVE-2024-5679

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Attacker Value
Unknown

CVE-2024-2602

Disclosure Date: July 11, 2024 (last updated July 13, 2024)
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
Attacker Value
Unknown

CVE-2024-5559

Disclosure Date: June 12, 2024 (last updated August 24, 2024)
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.
Attacker Value
Unknown

CVE-2024-2747

Disclosure Date: June 12, 2024 (last updated August 24, 2024)
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
Attacker Value
Unknown

CVE-2024-0865

Disclosure Date: June 12, 2024 (last updated July 20, 2024)
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
Attacker Value
Unknown

CVE-2024-5560

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.
Attacker Value
Unknown

CVE-2024-5558

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
Attacker Value
Unknown

CVE-2024-5557

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
Attacker Value
Unknown

CVE-2024-37040

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.