Записи LifeSize
5 опубликованных записей вендора lifesize.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 20 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2011-2763Готовый эксплойт | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a molifesize · lifesize room appliance · CWE-20 | Высокая7,5 | — | 36,1 % | 2 сент. 2011 г. |
37Наблюдать | CVE-2019-7632Эксплойта нет | LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharalifesize · team 220 firmware · CWE-78 | Высокая8,8 | — | 6,5 % | 8 февр. 2019 г. |
37Наблюдать | CVE-2019-3702Эксплойта нет | A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute lifesize · icon 300 firmware · CWE-78 | Высокая8,8 | — | 5,2 % | 13 мая 2019 г. |
24Наблюдать | CVE-2018-17981Эксплойта нет | Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.lifesize · express 220 firmware · CWE-79 | Средняя6,1 | — | 0,8 % | 21 янв. 2020 г. |
21Наблюдать | CVE-2011-2762Эксплойта нет | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data asslifesize · lifesize room appliance software · CWE-287 | Средняя5,0 | — | 2,3 % | 2 сент. 2011 г. |
- CVE-2011-276341В плане
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a mo
ВысокаяCVSS 7,5Готовый эксплойтEPSS 36 %lifesize · lifesize room appliance2 сент. 2011 г.
- CVE-2019-763237Наблюдать
LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metachara
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %lifesize · team 220 firmware8 февр. 2019 г.
- CVE-2019-370237Наблюдать
A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %lifesize · icon 300 firmware13 мая 2019 г.
- CVE-2018-1798124Наблюдать
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %lifesize · express 220 firmware21 янв. 2020 г.
- CVE-2011-276221Наблюдать
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data ass
СредняяCVSS 5,0Эксплойта нетEPSS 2 %lifesize · lifesize room appliance software2 сент. 2011 г.