Записи Janitza
9 опубликованных записей вендора janitza.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-254 7PK - Security Features2
- CWE-255 Credentials Management Errors1
- CWE-284 Improper Access Control1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2015-3972Эксплойта нет | The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easiejanitza · umg 508 · CWE-254 | Критическая10,0 | — | 2,9 % | 28 окт. 2015 г. |
35Наблюдать | CVE-2023-50894Эксплойта нет | In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password janitza · gridvis · CWE-200 | Высокая8,8 | — | 0,4 % | 26 мар. 2024 г. |
31Наблюдать | CVE-2015-3968Эксплойта нет | The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to reajanitza · umg 508 · CWE-255 | Высокая7,5 | — | 2,3 % | 28 окт. 2015 г. |
30Наблюдать | CVE-2015-3971Эксплойта нет | The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to reajanitza · umg 508 · CWE-284 | Высокая7,5 | — | 1,6 % | 28 окт. 2015 г. |
28Наблюдать | CVE-2023-50895Эксплойта нет | In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functijanitza · gridvis | Высокая7,2 | — | 0,7 % | 26 мар. 2024 г. |
27Наблюдать | CVE-2015-3967Эксплойта нет | Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the autjanitza · umg 508 · CWE-352 | Средняя6,8 | — | 0,6 % | 28 окт. 2015 г. |
20Наблюдать | CVE-2015-3973Эксплойта нет | Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine janitza · umg 508 · CWE-254 | Средняя5,0 | — | 1,5 % | 28 окт. 2015 г. |
20Наблюдать | CVE-2015-3969Эксплойта нет | Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to Ujanitza · umg 508 · CWE-200 | Средняя5,0 | — | 1,4 % | 28 окт. 2015 г. |
17Наблюдать | CVE-2015-3970Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attjanitza · umg 508 · CWE-79 | Средняя4,3 | — | 1,1 % | 28 окт. 2015 г. |
- CVE-2015-397241В плане
The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easie
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %janitza · umg 50828 окт. 2015 г.
- CVE-2023-5089435Наблюдать
In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %janitza · gridvis26 мар. 2024 г.
- CVE-2015-396831Наблюдать
The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to rea
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %janitza · umg 50828 окт. 2015 г.
- CVE-2015-397130Наблюдать
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to rea
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %janitza · umg 50828 окт. 2015 г.
- CVE-2023-5089528Наблюдать
In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functi
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %janitza · gridvis26 мар. 2024 г.
- CVE-2015-396727Наблюдать
Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the aut
СредняяCVSS 6,8Эксплойта нетEPSS 1 %janitza · umg 50828 окт. 2015 г.
- CVE-2015-397320Наблюдать
Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine
СредняяCVSS 5,0Эксплойта нетEPSS 1 %janitza · umg 50828 окт. 2015 г.
- CVE-2015-396920Наблюдать
Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to U
СредняяCVSS 5,0Эксплойта нетEPSS 1 %janitza · umg 50828 окт. 2015 г.
- CVE-2015-397017Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote att
СредняяCVSS 4,3Эксплойта нетEPSS 1 %janitza · umg 50828 окт. 2015 г.