Записи Vertiv
8 опубликованных записей вендора vertiv.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2018-10079Proof of concept | Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuravertiv · watchdog console · CWE-269 | Высокая7,8 | — | 0,8 % | 20 апр. 2018 г. |
31Наблюдать | CVE-2015-7260Эксплойта нет | Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.vertiv · liebert multilink automated shutdown · CWE-264 | Высокая7,8 | — | 0,3 % | 9 апр. 2017 г. |
30Наблюдать | CVE-2018-12922Эксплойта нет | Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/covertiv · liebert intellislot firmware · CWE-732 | Высокая7,5 | — | 1,6 % | 28 июн. 2018 г. |
29Наблюдать | CVE-2019-9507Эксплойта нет | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to arbitrary remote code executionvertiv · avocent umg-4000 firmware · CWE-95 | Высокая7,2 | — | 2,2 % | 30 мар. 2020 г. |
21Наблюдать | CVE-2018-10077Proof of concept | XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files vvertiv · watchdog console · CWE-611 | Средняя4,9 | — | 8,1 % | 20 апр. 2018 г. |
21Наблюдать | CVE-2019-9509Эксплойта нет | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected cross site scriptingvertiv · avocent umg-4000 firmware · CWE-79 | Средняя5,4 | — | 0,9 % | 30 мар. 2020 г. |
20Наблюдать | CVE-2018-10078Proof of concept | Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web vertiv · watchdog console · CWE-79 | Средняя4,8 | — | 2,0 % | 20 апр. 2018 г. |
14Наблюдать | CVE-2019-9508Эксплойта нет | Vertiv Avocent UMG-4000 version 4.2.1.19 web interface is vulnerable to stored cross site scriptingvertiv · avocent umg-4000 firmware · CWE-79 | Низкая3,5 | — | 0,6 % | 30 мар. 2020 г. |
- CVE-2018-1007931Наблюдать
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configura
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %vertiv · watchdog console20 апр. 2018 г.
- CVE-2015-726031Наблюдать
Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %vertiv · liebert multilink automated shutdown9 апр. 2017 г.
- CVE-2018-1292230Наблюдать
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/co
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vertiv · liebert intellislot firmware28 июн. 2018 г.
- CVE-2019-950729Наблюдать
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to arbitrary remote code execution
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %vertiv · avocent umg-4000 firmware30 мар. 2020 г.
- CVE-2018-1007721Наблюдать
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files v
СредняяCVSS 4,9Proof of conceptEPSS 8 %vertiv · watchdog console20 апр. 2018 г.
- CVE-2019-950921Наблюдать
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %vertiv · avocent umg-4000 firmware30 мар. 2020 г.
- CVE-2018-1007820Наблюдать
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web
СредняяCVSS 4,8Proof of conceptEPSS 2 %vertiv · watchdog console20 апр. 2018 г.
- CVE-2019-950814Наблюдать
Vertiv Avocent UMG-4000 version 4.2.1.19 web interface is vulnerable to stored cross site scripting
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %vertiv · avocent umg-4000 firmware30 мар. 2020 г.