Show filters
69 Total Results
Displaying 1-10 of 69
Sort by:
Attacker Value
Unknown

CVE-2024-7695

Disclosure Date: January 29, 2025 (last updated February 23, 2025)
Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory outside the bounds of the buffer. Successful exploitation of this vulnerability could result in a denial-of-service attack.
0
Attacker Value
Unknown

CVE-2024-9404

Disclosure Date: December 04, 2024 (last updated February 27, 2025)
This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability poses a significant remote threat, potentially allowing attackers to shut down affected systems.
0
Attacker Value
Unknown

CVE-2024-9137

Disclosure Date: October 14, 2024 (last updated February 26, 2025)
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.
0
Attacker Value
Unknown

CVE-2023-33413

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
Attacker Value
Unknown

CVE-2023-33412

Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
Attacker Value
Unknown

CVE-2023-33411

Disclosure Date: December 07, 2023 (last updated February 25, 2025)
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
Attacker Value
Unknown

CVE-2023-34853

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
Attacker Value
Unknown

CVE-2023-25366

Disclosure Date: June 16, 2023 (last updated February 25, 2025)
In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.
Attacker Value
Unknown

CVE-2023-25369

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Denial of Service on the user interface triggered by malformed SCPI command.
Attacker Value
Unknown

CVE-2023-25368

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can overwrite firmnware.