dw records
7 published records for vendor dw.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-34538No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vdw · megapix firmware · CWE-78 | High8.8 | — | 2.7% | Jul 19, 2022 |
35Monitor | CVE-2022-34540No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vdw · megapix firmware · CWE-78 | High8.8 | — | 1.2% | Jul 19, 2022 |
35Monitor | CVE-2022-34539No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/cdw · megapix firmware · CWE-78 | High8.8 | — | 1.2% | Jul 19, 2022 |
31Monitor | CVE-2022-34534Proof of concept | Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.dw · spectrum server firmware | High7.5 | — | 2.5% | Jul 19, 2022 |
30Monitor | CVE-2022-34535No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.dw · megapix firmware · CWE-287 | High7.5 | — | 0.8% | Jul 19, 2022 |
30Monitor | CVE-2022-34536No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafdw · megapix firmware · CWE-384 | High7.5 | — | 0.7% | Jul 19, 2022 |
21Monitor | CVE-2022-34537No exploit | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the componendw · megapix firmware · CWE-79 | Medium5.4 | — | 0.4% | Jul 19, 2022 |
- CVE-2022-3453836Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/v
HighCVSS 8.8No exploitEPSS 3%dw · megapix firmwareJul 19, 2022
- CVE-2022-3454035Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/v
HighCVSS 8.8No exploitEPSS 1%dw · megapix firmwareJul 19, 2022
- CVE-2022-3453935Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/c
HighCVSS 8.8No exploitEPSS 1%dw · megapix firmwareJul 19, 2022
- CVE-2022-3453431Monitor
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
HighCVSS 7.5Proof of conceptEPSS 3%dw · spectrum server firmwareJul 19, 2022
- CVE-2022-3453530Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
HighCVSS 7.5No exploitEPSS 1%dw · megapix firmwareJul 19, 2022
- CVE-2022-3453630Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a craf
HighCVSS 7.5No exploitEPSS 1%dw · megapix firmwareJul 19, 2022
- CVE-2022-3453721Monitor
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the componen
MediumCVSS 5.4No exploitEPSS 0%dw · megapix firmwareJul 19, 2022