elenos kayıtları
elenos üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-204 Observable Response Discrepancy1
- CWE-281 Improper Preservation of Permissions1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-613 Insufficient Session Expiration1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2023-34671İstismar yok | Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's roelenos · etg150 fm firmware | Yüksek8,8 | — | %0,9 | 23 Haz 2023 |
35İzleyin | CVE-2023-34672İstismar yok | Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting uelenos · etg150 firmware · CWE-281 | Yüksek8,8 | — | %0,7 | 23 Haz 2023 |
30İzleyin | CVE-2023-37832İstismar yok | A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unelenos · etg150 firmware · CWE-307 | Yüksek7,5 | — | %0,5 | 31 Eki 2023 |
26İzleyin | CVE-2023-34673İstismar yok | Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploielenos · etg150 firmware | Orta6,5 | — | %0,7 | 23 Haz 2023 |
26İzleyin | CVE-2023-45396İstismar yok | An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version elenos · etg150 firmware · CWE-639 | Orta6,5 | — | %0,4 | 11 Eki 2023 |
21İzleyin | CVE-2023-37831İstismar yok | An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentelenos · etg150 firmware · CWE-204 | Orta5,3 | — | %0,5 | 31 Eki 2023 |
21İzleyin | CVE-2023-39695İstismar yok | Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and delenos · etg150 firmware · CWE-613 | Orta5,3 | — | %0,4 | 31 Eki 2023 |
10İzleyin | CVE-2023-37833İstismar yok | Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed elenos · etg150 firmware · CWE-20 | Düşük2,7 | — | %0,4 | 31 Eki 2023 |
- CVE-2023-3467135İzleyin
Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's ro
YüksekCVSS 8,8İstismar yokEPSS %1elenos · etg150 fm firmware23 Haz 2023
- CVE-2023-3467235İzleyin
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting u
YüksekCVSS 8,8İstismar yokEPSS %1elenos · etg150 firmware23 Haz 2023
- CVE-2023-3783230İzleyin
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other un
YüksekCVSS 7,5İstismar yokEPSS %1elenos · etg150 firmware31 Eki 2023
- CVE-2023-3467326İzleyin
Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploi
OrtaCVSS 6,5İstismar yokEPSS %1elenos · etg150 firmware23 Haz 2023
- CVE-2023-4539626İzleyin
An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version
OrtaCVSS 6,5İstismar yokEPSS %0elenos · etg150 firmware11 Eki 2023
- CVE-2023-3783121İzleyin
An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credent
OrtaCVSS 5,3İstismar yokEPSS %0elenos · etg150 firmware31 Eki 2023
- CVE-2023-3969521İzleyin
Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and d
OrtaCVSS 5,3İstismar yokEPSS %0elenos · etg150 firmware31 Eki 2023
- CVE-2023-3783310İzleyin
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed
DüşükCVSS 2,7İstismar yokEPSS %0elenos · etg150 firmware31 Eki 2023