proges kayıtları
proges üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-121 Stack-based Buffer Overflow1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-256 Plaintext Storage of a Password1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-428 Unquoted Search Path or Element1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2024-3083İstismar yok | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrativeproges · sensor net connect firmware v2 · CWE-352 | Yüksek8,3 | — | %0,2 | 31 Tem 2024 |
31İzleyin | CVE-2024-31202İstismar yok | A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perforproges · thermoscan ip · CWE-732 | Yüksek7,8 | — | %0,2 | 31 Tem 2024 |
26İzleyin | CVE-2024-31201İstismar yok | A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.proges · thermoscan ip · CWE-428 | Orta6,7 | — | %0,2 | 31 Tem 2024 |
24İzleyin | CVE-2024-31199İstismar yok | A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injecproges · sensor net connect firmware v2 · CWE-79 | Orta6,1 | — | %0,3 | 31 Tem 2024 |
22İzleyin | CVE-2024-31203İstismar yok | A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attackeproges · thermoscan ip · CWE-121 | Orta5,5 | — | %0,1 | 31 Tem 2024 |
18İzleyin | CVE-2024-31200İstismar yok | A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access proges · sensor net connect firmware v2 · CWE-201 | Orta4,6 | — | %0,2 | 31 Tem 2024 |
18İzleyin | CVE-2024-3082İstismar yok | A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to proges · sensor net connect firmware v2 · CWE-256 | Orta4,6 | — | %0,1 | 31 Tem 2024 |
- CVE-2024-308333İzleyin
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative
YüksekCVSS 8,3İstismar yokEPSS %0proges · sensor net connect firmware v231 Tem 2024
- CVE-2024-3120231İzleyin
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perfor
YüksekCVSS 7,8İstismar yokEPSS %0proges · thermoscan ip31 Tem 2024
- CVE-2024-3120126İzleyin
A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service.
OrtaCVSS 6,7İstismar yokEPSS %0proges · thermoscan ip31 Tem 2024
- CVE-2024-3119924İzleyin
A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently injec
OrtaCVSS 6,1İstismar yokEPSS %0proges · sensor net connect firmware v231 Tem 2024
- CVE-2024-3120322İzleyin
A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacke
OrtaCVSS 5,5İstismar yokEPSS %0proges · thermoscan ip31 Tem 2024
- CVE-2024-3120018İzleyin
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access
OrtaCVSS 4,6İstismar yokEPSS %0proges · sensor net connect firmware v231 Tem 2024
- CVE-2024-308218İzleyin
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to
OrtaCVSS 4,6İstismar yokEPSS %0proges · sensor net connect firmware v231 Tem 2024