relyum records
14 published records for vendor relyum.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control2
- CWE-862 Missing Authorization1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-47577No exploit | An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current passrelyum · rely-pcie firmware · CWE-522 | Critical9.8 | — | 0.7% | Dec 12, 2023 |
35Monitor | CVE-2023-47576No exploit | An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web intrelyum · rely-pcie firmware · CWE-77 | High8.8 | — | 1.5% | Dec 12, 2023 |
35Monitor | CVE-2024-44577No exploit | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.relyum · rely-pcie firmware · CWE-77 | High8.8 | — | 1.0% | Sep 11, 2024 |
35Monitor | CVE-2024-44572No exploit | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.relyum · rely-pcie firmware · CWE-77 | High8.8 | — | 1.0% | Sep 11, 2024 |
35Monitor | CVE-2024-44574No exploit | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.relyum · rely-pcie firmware · CWE-77 | High8.8 | — | 1.0% | Sep 11, 2024 |
35Monitor | CVE-2023-47573No exploit | An issue discovered in Relyum RELY-PCIe 22.2.1 devices.relyum · rely-pcie firmware · CWE-862 | High8.8 | — | 0.7% | Dec 12, 2023 |
35Monitor | CVE-2024-44570No exploit | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.relyum · rely-pcie firmware · CWE-77 | High8.8 | — | 0.5% | Sep 11, 2024 |
35Monitor | CVE-2024-44571No exploit | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.relyum · rely-pcie firmware · CWE-284 | High8.8 | — | 0.4% | Sep 11, 2024 |
35Monitor | CVE-2023-47578No exploit | Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF relyum · rely-pcie firmware · CWE-352 | High8.8 | — | 0.3% | Dec 12, 2023 |
30Monitor | CVE-2023-47579No exploit | Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the orelyum · rely-pcie firmware · CWE-284 | High7.5 | — | 0.6% | Dec 12, 2023 |
24Monitor | CVE-2023-47575No exploit | An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices.relyum · rely-pcie firmware · CWE-79 | Medium6.1 | — | 0.4% | Dec 12, 2023 |
23Monitor | CVE-2023-47574No exploit | An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices.relyum · rely-pcie firmware | Medium5.9 | — | 0.5% | Dec 12, 2023 |
18Monitor | CVE-2024-44573No exploit | A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbirelyum · rely-pcie firmware · CWE-79 | Medium4.7 | — | 0.3% | Sep 11, 2024 |
14Monitor | CVE-2024-44575No exploit | RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to relyum · rely-pcie firmware · CWE-732 | Low3.7 | — | 0.3% | Sep 11, 2024 |
- CVE-2023-4757739Monitor
An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current pass
CriticalCVSS 9.8No exploitEPSS 1%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2023-4757635Monitor
An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web int
HighCVSS 8.8No exploitEPSS 2%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2024-4457735Monitor
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
HighCVSS 8.8No exploitEPSS 1%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2024-4457235Monitor
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
HighCVSS 8.8No exploitEPSS 1%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2024-4457435Monitor
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
HighCVSS 8.8No exploitEPSS 1%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2023-4757335Monitor
An issue discovered in Relyum RELY-PCIe 22.2.1 devices.
HighCVSS 8.8No exploitEPSS 1%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2024-4457035Monitor
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.
HighCVSS 8.8No exploitEPSS 0%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2024-4457135Monitor
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
HighCVSS 8.8No exploitEPSS 0%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2023-4757835Monitor
Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF
HighCVSS 8.8No exploitEPSS 0%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2023-4757930Monitor
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the o
HighCVSS 7.5No exploitEPSS 1%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2023-4757524Monitor
An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices.
MediumCVSS 6.1No exploitEPSS 0%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2023-4757423Monitor
An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices.
MediumCVSS 5.9No exploitEPSS 0%relyum · rely-pcie firmwareDec 12, 2023
- CVE-2024-4457318Monitor
A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbi
MediumCVSS 4.7No exploitEPSS 0%relyum · rely-pcie firmwareSep 11, 2024
- CVE-2024-4457514Monitor
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to
LowCVSS 3.7No exploitEPSS 0%relyum · rely-pcie firmwareSep 11, 2024