Show filters
386 Total Results
Displaying 51-60 of 386
Sort by:
Attacker Value
Unknown
CVE-2023-4299
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.
0
Attacker Value
Unknown
CVE-2023-20221
Disclosure Date: August 16, 2023 (last updated January 25, 2024)
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based management interface of an affected system.
This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform a factory reset of the affected device, resulting in a Denial of Service (DoS) condition.
0
Attacker Value
Unknown
CVE-2023-32453
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without knowledge of the BIOS administrator.
0
Attacker Value
Unknown
CVE-2023-28075
Disclosure Date: August 16, 2023 (last updated October 08, 2023)
Dell BIOS contain a Time-of-check Time-of-use vulnerability in BIOS. A local authenticated malicious user with physical access to the system could potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI in order to gain arbitrary code execution on the system.
0
Attacker Value
Unknown
CVE-2023-26299
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.
0
Attacker Value
Unknown
CVE-2023-28064
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Dell BIOS contains an Out-of-bounds Write vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
0
Attacker Value
Unknown
CVE-2023-28060
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
0
Attacker Value
Unknown
CVE-2023-28058
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
0
Attacker Value
Unknown
CVE-2023-28050
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
0
Attacker Value
Unknown
CVE-2023-28044
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
0