Перейти к содержимому
Noroxi

Записи proges

7 опубликованных записей вендора proges.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 24

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

7 записей
  • CVE-2024-3083
    33Наблюдать

    A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    proges · sensor net connect firmware v231 июл. 2024 г.

  • CVE-2024-31202
    31Наблюдать

    A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perfor

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    proges · thermoscan ip31 июл. 2024 г.

  • CVE-2024-31201
    26Наблюдать

    A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    proges · thermoscan ip31 июл. 2024 г.

  • CVE-2024-31199
    24Наблюдать

    A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injec

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    proges · sensor net connect firmware v231 июл. 2024 г.

  • CVE-2024-31203
    22Наблюдать

    A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacke

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    proges · thermoscan ip31 июл. 2024 г.

  • CVE-2024-31200
    18Наблюдать

    A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    proges · sensor net connect firmware v231 июл. 2024 г.

  • CVE-2024-3082
    18Наблюдать

    A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    proges · sensor net connect firmware v231 июл. 2024 г.