micasaverde kayıtları
micasaverde üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-863 Incorrect Authorization1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2013-4864Kavram kanıtı | MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bimicasaverde · veralite firmware · CWE-918 | Kritik9,8 | — | %6,3 | 28 Oca 2020 |
39İzleyin | CVE-2013-4863Kavram kanıtı | The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code vimicasaverde · veralite firmware · CWE-287 | Yüksek8,8 | — | %12,2 | 28 Oca 2020 |
33İzleyin | CVE-2013-4862Kavram kanıtı | MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmmicasaverde · veralite firmware · CWE-863 | Yüksek8,1 | — | %3,7 | 28 Oca 2020 |
28İzleyin | CVE-2013-4861Kavram kanıtı | Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated usersmicasaverde · veralite firmware · CWE-22 | Orta6,5 | — | %6,6 | 28 Oca 2020 |
27İzleyin | CVE-2013-4865Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers tomicasaverde · veralite firmware · CWE-352 | Orta6,5 | — | %1,7 | 28 Oca 2020 |
- CVE-2013-486441Planlayın
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bi
KritikCVSS 9,8Kavram kanıtıEPSS %6micasaverde · veralite firmware28 Oca 2020
- CVE-2013-486339İzleyin
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code vi
YüksekCVSS 8,8Kavram kanıtıEPSS %12micasaverde · veralite firmware28 Oca 2020
- CVE-2013-486233İzleyin
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firm
YüksekCVSS 8,1Kavram kanıtıEPSS %4micasaverde · veralite firmware28 Oca 2020
- CVE-2013-486128İzleyin
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users
OrtaCVSS 6,5Kavram kanıtıEPSS %7micasaverde · veralite firmware28 Oca 2020
- CVE-2013-486527İzleyin
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to
OrtaCVSS 6,5Kavram kanıtıEPSS %2micasaverde · veralite firmware28 Oca 2020