proges records
7 published records for vendor proges.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-121 Stack-based Buffer Overflow1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-256 Plaintext Storage of a Password1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-428 Unquoted Search Path or Element1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
33Monitor | CVE-2024-3083No exploit | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrativeproges · sensor net connect firmware v2 · CWE-352 | High8.3 | — | 0.2% | Jul 31, 2024 |
31Monitor | CVE-2024-31202No exploit | A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perforproges · thermoscan ip · CWE-732 | High7.8 | — | 0.2% | Jul 31, 2024 |
26Monitor | CVE-2024-31201No exploit | A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.proges · thermoscan ip · CWE-428 | Medium6.7 | — | 0.2% | Jul 31, 2024 |
24Monitor | CVE-2024-31199No exploit | A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injecproges · sensor net connect firmware v2 · CWE-79 | Medium6.1 | — | 0.3% | Jul 31, 2024 |
22Monitor | CVE-2024-31203No exploit | A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attackeproges · thermoscan ip · CWE-121 | Medium5.5 | — | 0.1% | Jul 31, 2024 |
18Monitor | CVE-2024-31200No exploit | A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access proges · sensor net connect firmware v2 · CWE-201 | Medium4.6 | — | 0.2% | Jul 31, 2024 |
18Monitor | CVE-2024-3082No exploit | A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to proges · sensor net connect firmware v2 · CWE-256 | Medium4.6 | — | 0.1% | Jul 31, 2024 |
- CVE-2024-308333Monitor
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative
HighCVSS 8.3No exploitEPSS 0%proges · sensor net connect firmware v2Jul 31, 2024
- CVE-2024-3120231Monitor
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perfor
HighCVSS 7.8No exploitEPSS 0%proges · thermoscan ipJul 31, 2024
- CVE-2024-3120126Monitor
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.
MediumCVSS 6.7No exploitEPSS 0%proges · thermoscan ipJul 31, 2024
- CVE-2024-3119924Monitor
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injec
MediumCVSS 6.1No exploitEPSS 0%proges · sensor net connect firmware v2Jul 31, 2024
- CVE-2024-3120322Monitor
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacke
MediumCVSS 5.5No exploitEPSS 0%proges · thermoscan ipJul 31, 2024
- CVE-2024-3120018Monitor
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access
MediumCVSS 4.6No exploitEPSS 0%proges · sensor net connect firmware v2Jul 31, 2024
- CVE-2024-308218Monitor
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to
MediumCVSS 4.6No exploitEPSS 0%proges · sensor net connect firmware v2Jul 31, 2024