LifeSize kayıtları
lifesize üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %20
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2011-2763Silahlaştırılmış | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a molifesize · lifesize room appliance · CWE-20 | Yüksek7,5 | — | %36,1 | 2 Eyl 2011 |
37İzleyin | CVE-2019-7632İstismar yok | LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharalifesize · team 220 firmware · CWE-78 | Yüksek8,8 | — | %6,5 | 8 Şub 2019 |
37İzleyin | CVE-2019-3702İstismar yok | A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute lifesize · icon 300 firmware · CWE-78 | Yüksek8,8 | — | %5,2 | 13 May 2019 |
24İzleyin | CVE-2018-17981İstismar yok | Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.lifesize · express 220 firmware · CWE-79 | Orta6,1 | — | %0,8 | 21 Oca 2020 |
21İzleyin | CVE-2011-2762İstismar yok | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data asslifesize · lifesize room appliance software · CWE-287 | Orta5,0 | — | %2,3 | 2 Eyl 2011 |
- CVE-2011-276341Planlayın
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a mo
YüksekCVSS 7,5SilahlaştırılmışEPSS %36lifesize · lifesize room appliance2 Eyl 2011
- CVE-2019-763237İzleyin
LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metachara
YüksekCVSS 8,8İstismar yokEPSS %6lifesize · team 220 firmware8 Şub 2019
- CVE-2019-370237İzleyin
A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute
YüksekCVSS 8,8İstismar yokEPSS %5lifesize · icon 300 firmware13 May 2019
- CVE-2018-1798124İzleyin
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
OrtaCVSS 6,1İstismar yokEPSS %1lifesize · express 220 firmware21 Oca 2020
- CVE-2011-276221İzleyin
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data ass
OrtaCVSS 5,0İstismar yokEPSS %2lifesize · lifesize room appliance software2 Eyl 2011