Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2023-33469
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.
0
Attacker Value
Unknown
CVE-2023-33468
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
0
Attacker Value
Unknown
CVE-2023-33509
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2023-33508
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
0
Attacker Value
Unknown
CVE-2023-33507
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.
0
Attacker Value
Unknown
CVE-2021-36356
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.
0
Attacker Value
Unknown
CVE-2021-35064
Disclosure Date: July 12, 2021 (last updated February 23, 2025)
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.
0
Attacker Value
Unknown
CVE-2019-17124
Disclosure Date: October 09, 2019 (last updated November 27, 2024)
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
0