Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-3083

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.
Attacker Value
Unknown

CVE-2024-3082

Disclosure Date: July 31, 2024 (last updated September 30, 2024)
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.
Attacker Value
Unknown

CVE-2024-31203

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
Attacker Value
Unknown

CVE-2024-31202

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
Attacker Value
Unknown

CVE-2024-31201

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the C:\ path to attempt a privilege escalation on the local machine.
Attacker Value
Unknown

CVE-2024-31200

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext when an administrative session is open in the browser.
Attacker Value
Unknown

CVE-2024-31199

Disclosure Date: July 31, 2024 (last updated August 13, 2024)
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.
Attacker Value
Unknown

CVE-2020-8612

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
Attacker Value
Unknown

CVE-2020-8611

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements.