Skip to content
Noroxi

proges records

7 published records for vendor proges.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2024-3083
    33Monitor

    A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative

    HighCVSS 8.3No exploitEPSS 0%

    proges · sensor net connect firmware v2Jul 31, 2024

  • A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perfor

    HighCVSS 7.8No exploitEPSS 0%

    proges · thermoscan ipJul 31, 2024

  • A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.

    MediumCVSS 6.7No exploitEPSS 0%

    proges · thermoscan ipJul 31, 2024

  • A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injec

    MediumCVSS 6.1No exploitEPSS 0%

    proges · sensor net connect firmware v2Jul 31, 2024

  • A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacke

    MediumCVSS 5.5No exploitEPSS 0%

    proges · thermoscan ipJul 31, 2024

  • A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access

    MediumCVSS 4.6No exploitEPSS 0%

    proges · sensor net connect firmware v2Jul 31, 2024

  • CVE-2024-3082
    18Monitor

    A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to

    MediumCVSS 4.6No exploitEPSS 0%

    proges · sensor net connect firmware v2Jul 31, 2024