Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-41907

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.
Attacker Value
Unknown

CVE-2024-41906

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.
Attacker Value
Unknown

CVE-2024-41905

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.
Attacker Value
Unknown

CVE-2024-41904

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.
Attacker Value
Unknown

CVE-2024-41903

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data corruption.
Attacker Value
Unknown

CVE-2024-35212

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.
Attacker Value
Unknown

CVE-2024-35211

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”).
Attacker Value
Unknown

CVE-2024-35210

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information.
Attacker Value
Unknown

CVE-2024-35209

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files.
Attacker Value
Unknown

CVE-2024-35208

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords.