loftware records
8 published records for vendor loftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-259 Use of Hard-coded Password1
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-502 Deserialization of Untrusted Data1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-37227No exploit | Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.loftware · spectrum · CWE-502 | Critical9.8 | — | 0.6% | Sep 10, 2024 |
39Monitor | CVE-2023-37226No exploit | Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.loftware · spectrum · CWE-287 | Critical9.8 | — | 0.6% | Sep 10, 2024 |
39Monitor | CVE-2023-37231No exploit | Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.loftware · spectrum · CWE-259 | Critical9.8 | — | 0.5% | Sep 10, 2024 |
39Monitor | CVE-2023-37234No exploit | Loftware Spectrum through 4.6 has unprotected JMX Registry.loftware · spectrum · CWE-284 | Critical9.8 | — | 0.4% | Sep 10, 2024 |
35Monitor | CVE-2023-37233No exploit | Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.loftware · spectrum · CWE-611 | High8.8 | — | 0.4% | Sep 10, 2024 |
35Monitor | CVE-2023-37230No exploit | Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.loftware · spectrum · CWE-918 | High8.8 | — | 0.4% | Sep 10, 2024 |
35Monitor | CVE-2023-37229No exploit | Loftware Spectrum before 5.1 allows SSRF.loftware · spectrum · CWE-918 | High8.8 | — | 0.4% | Sep 10, 2024 |
30Monitor | CVE-2023-37232No exploit | Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.loftware · spectrum · CWE-200 | High7.5 | — | 0.4% | Sep 10, 2024 |
- CVE-2023-3722739Monitor
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
CriticalCVSS 9.8No exploitEPSS 1%loftware · spectrumSep 10, 2024
- CVE-2023-3722639Monitor
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
CriticalCVSS 9.8No exploitEPSS 1%loftware · spectrumSep 10, 2024
- CVE-2023-3723139Monitor
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
CriticalCVSS 9.8No exploitEPSS 1%loftware · spectrumSep 10, 2024
- CVE-2023-3723439Monitor
Loftware Spectrum through 4.6 has unprotected JMX Registry.
CriticalCVSS 9.8No exploitEPSS 0%loftware · spectrumSep 10, 2024
- CVE-2023-3723335Monitor
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
HighCVSS 8.8No exploitEPSS 0%loftware · spectrumSep 10, 2024
- CVE-2023-3723035Monitor
Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
HighCVSS 8.8No exploitEPSS 0%loftware · spectrumSep 10, 2024
- CVE-2023-3722935Monitor
Loftware Spectrum before 5.1 allows SSRF.
HighCVSS 8.8No exploitEPSS 0%loftware · spectrumSep 10, 2024
- CVE-2023-3723230Monitor
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
HighCVSS 7.5No exploitEPSS 0%loftware · spectrumSep 10, 2024