Show filters
52 Total Results
Displaying 1-10 of 52
Sort by:
Attacker Value
Unknown
CVE-2024-9677
Disclosure Date: October 22, 2024 (last updated December 21, 2024)
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
0
Attacker Value
Unknown
CVE-2023-6399
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
0
Attacker Value
Unknown
CVE-2023-6398
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1,
USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1,
NWA50AX firmware versions through 6.29(ABYW.3), WAC500 firmware versions through 6.65(ABVS.1), WAX300H firmware versions through 6.60(ACHF.1), and WBE660S firmware versions through 6.65(ACGG.1) could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device via FTP.
0
Attacker Value
Unknown
CVE-2023-48952
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48951
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48950
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48949
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48948
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48947
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0
Attacker Value
Unknown
CVE-2023-48946
Disclosure Date: November 29, 2023 (last updated December 01, 2023)
An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
0