Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-41907
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.
0
Attacker Value
Unknown
CVE-2024-41906
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
0
Attacker Value
Unknown
CVE-2024-41905
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.
0
Attacker Value
Unknown
CVE-2024-41904
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.
0
Attacker Value
Unknown
CVE-2024-41903
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data corruption.
0
Attacker Value
Unknown
CVE-2024-35212
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.
0
Attacker Value
Unknown
CVE-2024-35211
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).
0
Attacker Value
Unknown
CVE-2024-35210
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
0
Attacker Value
Unknown
CVE-2024-35209
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.
0
Attacker Value
Unknown
CVE-2024-35208
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.
0