Записи proges
7 опубликованных записей вендора proges.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-121 Stack-based Buffer Overflow1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-256 Plaintext Storage of a Password1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-428 Unquoted Search Path or Element1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
33Наблюдать | CVE-2024-3083Эксплойта нет | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrativeproges · sensor net connect firmware v2 · CWE-352 | Высокая8,3 | — | 0,2 % | 31 июл. 2024 г. |
31Наблюдать | CVE-2024-31202Эксплойта нет | A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perforproges · thermoscan ip · CWE-732 | Высокая7,8 | — | 0,2 % | 31 июл. 2024 г. |
26Наблюдать | CVE-2024-31201Эксплойта нет | A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.proges · thermoscan ip · CWE-428 | Средняя6,7 | — | 0,2 % | 31 июл. 2024 г. |
24Наблюдать | CVE-2024-31199Эксплойта нет | A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injecproges · sensor net connect firmware v2 · CWE-79 | Средняя6,1 | — | 0,3 % | 31 июл. 2024 г. |
22Наблюдать | CVE-2024-31203Эксплойта нет | A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attackeproges · thermoscan ip · CWE-121 | Средняя5,5 | — | 0,1 % | 31 июл. 2024 г. |
18Наблюдать | CVE-2024-31200Эксплойта нет | A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access proges · sensor net connect firmware v2 · CWE-201 | Средняя4,6 | — | 0,2 % | 31 июл. 2024 г. |
18Наблюдать | CVE-2024-3082Эксплойта нет | A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to proges · sensor net connect firmware v2 · CWE-256 | Средняя4,6 | — | 0,1 % | 31 июл. 2024 г. |
- CVE-2024-308333Наблюдать
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %proges · sensor net connect firmware v231 июл. 2024 г.
- CVE-2024-3120231Наблюдать
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perfor
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %proges · thermoscan ip31 июл. 2024 г.
- CVE-2024-3120126Наблюдать
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.
СредняяCVSS 6,7Эксплойта нетEPSS 0 %proges · thermoscan ip31 июл. 2024 г.
- CVE-2024-3119924Наблюдать
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injec
СредняяCVSS 6,1Эксплойта нетEPSS 0 %proges · sensor net connect firmware v231 июл. 2024 г.
- CVE-2024-3120322Наблюдать
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacke
СредняяCVSS 5,5Эксплойта нетEPSS 0 %proges · thermoscan ip31 июл. 2024 г.
- CVE-2024-3120018Наблюдать
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access
СредняяCVSS 4,6Эксплойта нетEPSS 0 %proges · sensor net connect firmware v231 июл. 2024 г.
- CVE-2024-308218Наблюдать
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to
СредняяCVSS 4,6Эксплойта нетEPSS 0 %proges · sensor net connect firmware v231 июл. 2024 г.