Show filters
315 Total Results
Displaying 1-10 of 315
Sort by:
Attacker Value
Moderate
CVE-2022-43939
Disclosure Date: April 03, 2023 (last updated February 14, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.
2
Attacker Value
High
CVE-2022-43769
Disclosure Date: April 03, 2023 (last updated February 14, 2025)
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
2
Attacker Value
Unknown
CVE-2024-57964
Disclosure Date: February 18, 2025 (last updated February 18, 2025)
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems.
This issue affects HVAC Energy Saving Program:.
0
Attacker Value
Unknown
CVE-2024-57963
Disclosure Date: February 18, 2025 (last updated February 18, 2025)
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems.
This issue affects USB-CONVERTERCABLE DRIVER:.
0
Attacker Value
Unknown
CVE-2024-10205
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
Authentication Bypass
vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics
component
).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00.
0
Attacker Value
Unknown
CVE-2024-45068
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA.
This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.
0
Attacker Value
Unknown
CVE-2024-9929
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A vulnerability exists in NSD570 that allows any authenticated
user to access all device logs disclosing login information with
timestamps.
0
Attacker Value
Unknown
CVE-2024-9928
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could
cause account takeover and unauthorized access to the system
when an attacker conducts brute-force attacks against the
equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second
between failed login attempts making it difficult to automate the
attacks.
0
Attacker Value
Unknown
CVE-2024-41156
Disclosure Date: October 29, 2024 (last updated December 21, 2024)
Profile files from TRO600 series radios are extracted in plain-text
and encrypted file formats. Profile files provide potential attackers
valuable configuration information about the Tropos network. Profiles
can only be exported by authenticated users with higher privilege of write access.
0
Attacker Value
Unknown
CVE-2024-41153
Disclosure Date: October 29, 2024 (last updated November 01, 2024)
Command injection vulnerability in the Edge Computing UI for the
TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the
web UI can execute commands on the device with root privileges,
far more extensive than what the write privilege intends.
0