Shelly kayıtları
shelly üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read1
- CWE-306 Missing Authentication for Critical Function1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-354 Improper Validation of Integrity Check Value1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2024-48776İstismar yok | An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update processCWE-306 | Yüksek7,5 | — | %0,4 | 11 Eki 2024 |
22İzleyin | CVE-2023-33383Kavram kanıtı | Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a devshelly · pro 4pm firmware · CWE-125 | Orta5,3 | — | %4,7 | 2 Ağu 2023 |
22İzleyin | CVE-2023-42144İstismar yok | Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.shelly · trv firmware · CWE-319 | Orta5,5 | — | %0,1 | 23 Oca 2024 |
21İzleyin | CVE-2023-42143İstismar yok | Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device shelly · trv firmware · CWE-354 | Orta5,4 | — | %0,2 | 23 Oca 2024 |
- CVE-2024-4877630İzleyin
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
YüksekCVSS 7,5İstismar yokEPSS %011 Eki 2024
- CVE-2023-3338322İzleyin
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a dev
OrtaCVSS 5,3Kavram kanıtıEPSS %5shelly · pro 4pm firmware2 Ağu 2023
- CVE-2023-4214422İzleyin
Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.
OrtaCVSS 5,5İstismar yokEPSS %0shelly · trv firmware23 Oca 2024
- CVE-2023-4214321İzleyin
Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device
OrtaCVSS 5,4İstismar yokEPSS %0shelly · trv firmware23 Oca 2024