Записи orange
8 опубликованных записей вендора orange.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-254 7PK - Security Features1
- CWE-330 Use of Insufficiently Random Values1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2018-20377Proof of concept | Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to orange · arv7519rw22 livebox 2.1 firmware | Критическая9,8 | — | 7,7 % | 23 дек. 2018 г. |
39Наблюдать | CVE-2018-18375Эксплойта нет | goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the orange · airbox firmware · CWE-330 | Критическая9,8 | — | 1,3 % | 15 окт. 2018 г. |
36Наблюдать | CVE-2014-3150Эксплойта нет | Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive orange · livebox 1.1 firmware · CWE-254 | Высокая8,8 | — | 1,9 % | 15 нояб. 2017 г. |
36Наблюдать | CVE-2018-20577Эксплойта нет | Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exeorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Критическая9,1 | — | 0,6 % | 28 дек. 2018 г. |
30Наблюдать | CVE-2018-18376Эксплойта нет | goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devicesorange · airbox firmware · CWE-200 | Высокая7,5 | — | 1,5 % | 15 окт. 2018 г. |
30Наблюдать | CVE-2018-20575Эксплойта нет | Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.orange · arv7519rw22 livebox 2.1 firmware · CWE-20 | Высокая7,5 | — | 1,0 % | 28 дек. 2018 г. |
30Наблюдать | CVE-2018-18377Эксплойта нет | goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to loginorange · airbox firmware · CWE-862 | Высокая7,5 | — | 0,9 % | 15 окт. 2018 г. |
21Наблюдать | CVE-2018-20576Эксплойта нет | Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calorange · arv7519rw22 livebox 2.1 firmware · CWE-352 | Средняя5,4 | — | 0,4 % | 28 дек. 2018 г. |
- CVE-2018-2037741В плане
Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to
КритическаяCVSS 9,8Proof of conceptEPSS 8 %orange · arv7519rw22 livebox 2.1 firmware23 дек. 2018 г.
- CVE-2018-1837539Наблюдать
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %orange · airbox firmware15 окт. 2018 г.
- CVE-2014-315036Наблюдать
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %orange · livebox 1.1 firmware15 нояб. 2017 г.
- CVE-2018-2057736Наблюдать
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.
- CVE-2018-1837630Наблюдать
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %orange · airbox firmware15 окт. 2018 г.
- CVE-2018-2057530Наблюдать
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.
- CVE-2018-1837730Наблюдать
goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to login
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %orange · airbox firmware15 окт. 2018 г.
- CVE-2018-2057621Наблюдать
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone cal
СредняяCVSS 5,4Эксплойта нетEPSS 0 %orange · arv7519rw22 livebox 2.1 firmware28 дек. 2018 г.