Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown

CVE-2024-9677

Disclosure Date: October 22, 2024 (last updated December 21, 2024)
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Attacker Value
Unknown

CVE-2023-6399

Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
Attacker Value
Unknown

CVE-2023-6398

Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1, NWA50AX firmware versions through 6.29(ABYW.3), WAC500 firmware versions through 6.65(ABVS.1), WAX300H firmware versions through 6.60(ACHF.1), and WBE660S firmware versions through 6.65(ACGG.1) could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device via FTP.
0
Attacker Value
Unknown

CVE-2023-48952

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48951

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48950

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48949

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48948

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48947

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
Attacker Value
Unknown

CVE-2023-48946

Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.