F-logic kayıtları
f-logic üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2024-25830Kavram kanıtı | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.f-logic · datacube3 firmware · CWE-22 | Kritik9,8 | — | %24,0 | 28 Şub 2024 |
45Planlayın | CVE-2024-31750Kavram kanıtı | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.f-logic · datacube3 firmware · CWE-89 | Kritik9,8 | — | %19,3 | 18 Nis 2024 |
43Planlayın | CVE-2024-34854İstismar yok | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`f-logic · datacube3 firmware · CWE-22 | Kritik9,8 | — | %12,8 | 28 May 2024 |
40Planlayın | CVE-2024-25833İstismar yok | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitf-logic · datacube3 · CWE-89 | Kritik9,8 | — | %2,8 | 28 Şub 2024 |
39İzleyin | CVE-2024-25832Kavram kanıtı | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of danf-logic · datacube3 · CWE-434 | Yüksek8,8 | — | %12,8 | 28 Şub 2024 |
30İzleyin | CVE-2023-5329İstismar yok | Field Logic DataCube4 Web API improper authenticationf-logic · datacube4 firmware · CWE-287 | Yüksek7,5 | — | %0,8 | 1 Eki 2023 |
28İzleyin | CVE-2024-7066İstismar yok | F-logic DataCube3 HTTP POST Request config_time_sync.php os command injectionf-logic · datacube3 firmware · CWE-78 | Orta6,9 | — | %3,4 | 24 Tem 2024 |
25İzleyin | CVE-2024-34852İstismar yok | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transf-logic · datacube3 firmware · CWE-77 | Orta6,3 | — | %1,6 | 28 May 2024 |
21İzleyin | CVE-2024-25831İstismar yok | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization.f-logic · datacube3 · CWE-79 | Orta5,4 | — | %0,6 | 28 Şub 2024 |
- CVE-2024-2583046Planlayın
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction.
KritikCVSS 9,8Kavram kanıtıEPSS %24f-logic · datacube3 firmware28 Şub 2024
- CVE-2024-3175045Planlayın
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %19f-logic · datacube3 firmware18 Nis 2024
- CVE-2024-3485443Planlayın
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
KritikCVSS 9,8İstismar yokEPSS %13f-logic · datacube3 firmware28 May 2024
- CVE-2024-2583340Planlayın
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbit
KritikCVSS 9,8İstismar yokEPSS %3f-logic · datacube328 Şub 2024
- CVE-2024-2583239İzleyin
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dan
YüksekCVSS 8,8Kavram kanıtıEPSS %13f-logic · datacube328 Şub 2024
- CVE-2023-532930İzleyin
Field Logic DataCube4 Web API improper authentication
YüksekCVSS 7,5İstismar yokEPSS %1f-logic · datacube4 firmware1 Eki 2023
- CVE-2024-706628İzleyin
F-logic DataCube3 HTTP POST Request config_time_sync.php os command injection
OrtaCVSS 6,9İstismar yokEPSS %3f-logic · datacube3 firmware24 Tem 2024
- CVE-2024-3485225İzleyin
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/trans
OrtaCVSS 6,3İstismar yokEPSS %2f-logic · datacube3 firmware28 May 2024
- CVE-2024-2583121İzleyin
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization.
OrtaCVSS 5,4İstismar yokEPSS %1f-logic · datacube328 Şub 2024