guoxinled kayıtları
guoxinled üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-203 Observable Discrepancy1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-798 Use of Hard-coded Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-38466İstismar yok | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.guoxinled · synthesis image system · CWE-798 | Kritik9,8 | — | %0,4 | 16 Haz 2024 |
39İzleyin | CVE-2024-38468İstismar yok | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.guoxinled · synthesis image system · CWE-640 | Kritik9,8 | — | %0,4 | 16 Haz 2024 |
30İzleyin | CVE-2024-38467İstismar yok | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.guoxinled · synthesis image system · CWE-200 | Yüksek7,5 | — | %0,4 | 16 Haz 2024 |
21İzleyin | CVE-2024-38465İstismar yok | Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus erroguoxinled · synthesis image system · CWE-203 | Orta5,3 | — | %0,3 | 16 Haz 2024 |
- CVE-2024-3846639İzleyin
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
KritikCVSS 9,8İstismar yokEPSS %0guoxinled · synthesis image system16 Haz 2024
- CVE-2024-3846839İzleyin
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
KritikCVSS 9,8İstismar yokEPSS %0guoxinled · synthesis image system16 Haz 2024
- CVE-2024-3846730İzleyin
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
YüksekCVSS 7,5İstismar yokEPSS %0guoxinled · synthesis image system16 Haz 2024
- CVE-2024-3846521İzleyin
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus erro
OrtaCVSS 5,3İstismar yokEPSS %0guoxinled · synthesis image system16 Haz 2024