Записи F-logic
9 опубликованных записей вендора f-logic.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2024-25830Proof of concept | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.f-logic · datacube3 firmware · CWE-22 | Критическая9,8 | — | 24,0 % | 28 февр. 2024 г. |
45В плане | CVE-2024-31750Proof of concept | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.f-logic · datacube3 firmware · CWE-89 | Критическая9,8 | — | 19,3 % | 18 апр. 2024 г. |
43В плане | CVE-2024-34854Эксплойта нет | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`f-logic · datacube3 firmware · CWE-22 | Критическая9,8 | — | 12,8 % | 28 мая 2024 г. |
40В плане | CVE-2024-25833Эксплойта нет | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitf-logic · datacube3 · CWE-89 | Критическая9,8 | — | 2,8 % | 28 февр. 2024 г. |
39Наблюдать | CVE-2024-25832Proof of concept | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of danf-logic · datacube3 · CWE-434 | Высокая8,8 | — | 12,8 % | 28 февр. 2024 г. |
30Наблюдать | CVE-2023-5329Эксплойта нет | Field Logic DataCube4 Web API improper authenticationf-logic · datacube4 firmware · CWE-287 | Высокая7,5 | — | 0,8 % | 1 окт. 2023 г. |
28Наблюдать | CVE-2024-7066Эксплойта нет | F-logic DataCube3 HTTP POST Request config_time_sync.php os command injectionf-logic · datacube3 firmware · CWE-78 | Средняя6,9 | — | 3,4 % | 24 июл. 2024 г. |
25Наблюдать | CVE-2024-34852Эксплойта нет | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transf-logic · datacube3 firmware · CWE-77 | Средняя6,3 | — | 1,6 % | 28 мая 2024 г. |
21Наблюдать | CVE-2024-25831Эксплойта нет | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization.f-logic · datacube3 · CWE-79 | Средняя5,4 | — | 0,6 % | 28 февр. 2024 г. |
- CVE-2024-2583046В плане
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.
КритическаяCVSS 9,8Proof of conceptEPSS 24 %f-logic · datacube3 firmware28 февр. 2024 г.
- CVE-2024-3175045В плане
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 19 %f-logic · datacube3 firmware18 апр. 2024 г.
- CVE-2024-3485443В плане
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %f-logic · datacube3 firmware28 мая 2024 г.
- CVE-2024-2583340В плане
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %f-logic · datacube328 февр. 2024 г.
- CVE-2024-2583239Наблюдать
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dan
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %f-logic · datacube328 февр. 2024 г.
- CVE-2023-532930Наблюдать
Field Logic DataCube4 Web API improper authentication
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %f-logic · datacube4 firmware1 окт. 2023 г.
- CVE-2024-706628Наблюдать
F-logic DataCube3 HTTP POST Request config_time_sync.php os command injection
СредняяCVSS 6,9Эксплойта нетEPSS 3 %f-logic · datacube3 firmware24 июл. 2024 г.
- CVE-2024-3485225Наблюдать
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/trans
СредняяCVSS 6,3Эксплойта нетEPSS 2 %f-logic · datacube3 firmware28 мая 2024 г.
- CVE-2024-2583121Наблюдать
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %f-logic · datacube328 февр. 2024 г.