altus kayıtları
altus üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2021-39244İstismar yok | Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the galtus · nexto nx3003 firmware · CWE-78 | Yüksek8,8 | — | %3,5 | 23 Ağu 2021 |
30İzleyin | CVE-2021-39245İstismar yok | Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices.altus · nexto nx3003 firmware · CWE-798 | Yüksek7,5 | — | %1,3 | 23 Ağu 2021 |
26İzleyin | CVE-2021-39243İstismar yok | Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint.altus · nexto nx3003 firmware · CWE-352 | Orta6,5 | — | %0,5 | 23 Ağu 2021 |
- CVE-2021-3924436İzleyin
Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the g
YüksekCVSS 8,8İstismar yokEPSS %3altus · nexto nx3003 firmware23 Ağu 2021
- CVE-2021-3924530İzleyin
Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices.
YüksekCVSS 7,5İstismar yokEPSS %1altus · nexto nx3003 firmware23 Ağu 2021
- CVE-2021-3924326İzleyin
Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint.
OrtaCVSS 6,5İstismar yokEPSS %1altus · nexto nx3003 firmware23 Ağu 2021