Show filters
207 Total Results
Displaying 51-60 of 207
Sort by:
Attacker Value
Unknown

CVE-2023-0683

Disclosure Date: May 01, 2023 (last updated October 08, 2023)
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
Attacker Value
Unknown

CVE-2023-29056

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.
Attacker Value
Unknown

CVE-2023-25495

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured
Attacker Value
Unknown

CVE-2023-29058

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Attacker Value
Unknown

CVE-2023-29057

Disclosure Date: April 28, 2023 (last updated October 08, 2023)
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
Attacker Value
Unknown

CVE-2023-24838

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.
Attacker Value
Unknown

CVE-2023-24837

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2022-27538

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2022-27537

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2021-3809

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.