connectize records
7 published records for vendor connectize.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-521 Weak Password Requirements1
- CWE-522 Insufficiently Protected Credentials1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-24049No exploit | An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credentconnectize · ac21000 g6 firmware · CWE-521 | Critical9.8 | — | 0.7% | Dec 4, 2023 |
39Monitor | CVE-2023-24051No exploit | A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute foconnectize · ac21000 g6 firmware · CWE-307 | Critical9.8 | — | 0.7% | Dec 4, 2023 |
39Monitor | CVE-2023-24052No exploit | An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionaconnectize · ac21000 g6 firmware · CWE-863 | Critical9.8 | — | 0.7% | Dec 4, 2023 |
35Monitor | CVE-2023-24048No exploit | Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via cconnectize · ac21000 g6 firmware · CWE-352 | High8.8 | — | 0.3% | Dec 4, 2023 |
27Monitor | CVE-2023-24046No exploit | An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in thconnectize · ac21000 g6 firmware · CWE-77 | Medium6.8 | — | 0.6% | Dec 4, 2023 |
27Monitor | CVE-2023-24047No exploit | An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges viaconnectize · ac21000 g6 firmware · CWE-522 | Medium6.8 | — | 0.4% | Dec 4, 2023 |
21Monitor | CVE-2023-24050No exploit | Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string wconnectize · ac21000 g6 firmware · CWE-79 | Medium5.4 | — | 0.4% | Dec 4, 2023 |
- CVE-2023-2404939Monitor
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credent
CriticalCVSS 9.8No exploitEPSS 1%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2405139Monitor
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute fo
CriticalCVSS 9.8No exploitEPSS 1%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2405239Monitor
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functiona
CriticalCVSS 9.8No exploitEPSS 1%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2404835Monitor
Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via c
HighCVSS 8.8No exploitEPSS 0%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2404627Monitor
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in th
MediumCVSS 6.8No exploitEPSS 1%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2404727Monitor
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via
MediumCVSS 6.8No exploitEPSS 0%connectize · ac21000 g6 firmwareDec 4, 2023
- CVE-2023-2405021Monitor
Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string w
MediumCVSS 5.4No exploitEPSS 0%connectize · ac21000 g6 firmwareDec 4, 2023