Show filters
192 Total Results
Displaying 71-80 of 192
Sort by:
Attacker Value
Unknown

CVE-2023-41966

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
Attacker Value
Unknown

CVE-2023-26597

Disclosure Date: July 13, 2023 (last updated April 22, 2024)
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.
Attacker Value
Unknown

CVE-2023-25770

Disclosure Date: July 13, 2023 (last updated April 22, 2024)
Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
Attacker Value
Unknown

CVE-2023-25178

Disclosure Date: July 13, 2023 (last updated April 22, 2024)
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.
Attacker Value
Unknown

CVE-2023-24480

Disclosure Date: July 13, 2023 (last updated April 22, 2024)
Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading and versioning.
Attacker Value
Unknown

CVE-2022-43969

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
Attacker Value
Unknown

CVE-2023-20076

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system.
Attacker Value
Unknown

CVE-2022-39070

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.
Attacker Value
Unknown

CVE-2022-29588

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.
Attacker Value
Unknown

CVE-2022-29587

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.