Show filters
796 Total Results
Displaying 51-60 of 796
Sort by:
Attacker Value
Unknown

CVE-2024-37039

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
Attacker Value
Unknown

CVE-2024-37038

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
Attacker Value
Unknown

CVE-2024-37037

Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-37036

Disclosure Date: June 12, 2024 (last updated August 15, 2024)
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
Attacker Value
Unknown

CVE-2024-5313

Disclosure Date: June 12, 2024 (last updated August 15, 2024)
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts are limited to port scanning and fingerprinting activities as well as attempts to perform a potential denial of service attack on the exposed SSH interface.
Attacker Value
Unknown

CVE-2024-5056

Disclosure Date: June 12, 2024 (last updated August 24, 2024)
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
Attacker Value
Unknown

CVE-2024-2229

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user.
0
Attacker Value
Unknown

CVE-2024-2052

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker modifies the URL to download to a different location.
0
Attacker Value
Unknown

CVE-2024-2051

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.
0
Attacker Value
Unknown

CVE-2024-2050

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the context of the product.
0