Show filters
90 Total Results
Displaying 1-10 of 90
Sort by:
Attacker Value
Unknown

CVE-2021-3519

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Attacker Value
Unknown

CVE-2024-10498

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device which could result in invalid data or loss of web interface functionality.
0
Attacker Value
Unknown

CVE-2024-10497

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.
0
Attacker Value
Unknown

CVE-2024-11999

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
0
Attacker Value
Unknown

CVE-2024-8036

Disclosure Date: October 25, 2024 (last updated October 26, 2024)
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or allowing the attacker to take control of the node.
0
Attacker Value
Unknown

CVE-2024-48870

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
Attacker Value
Unknown

CVE-2024-47801

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
Attacker Value
Unknown

CVE-2024-47549

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
Attacker Value
Unknown

CVE-2024-47406

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
Attacker Value
Unknown

CVE-2024-47005

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.