Verizon kayıtları
verizon üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %9,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-287 Improper Authentication4
- CWE-521 Weak Password Requirements2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-28375İstismar yok | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile fverizon · lvskihp outdoorunit firmware · CWE-78 | Kritik9,8 | — | %2,3 | 14 Tem 2022 |
40Planlayın | CVE-2022-28373İstismar yok | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition functverizon · lvskihp indoorunit firmware · CWE-78 | Kritik9,8 | — | %2,3 | 14 Tem 2022 |
39İzleyin | CVE-2022-28369İstismar yok | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-opverizon · lvskihp indoorunit firmware · CWE-434 | Kritik9,8 | — | %1,5 | 14 Tem 2022 |
37İzleyin | CVE-2019-3914İstismar yok | Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated averizon · fios quantum gateway g1100 firmware · CWE-78 | Yüksek7,2 | — | %29,9 | 11 Nis 2019 |
36İzleyin | CVE-2022-28374İstismar yok | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settverizon · lvskihp outdoorunit firmware · CWE-78 | Yüksek8,8 | — | %2,3 | 14 Tem 2022 |
33İzleyin | CVE-2020-7660İstismar yok | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".verizon · serialize-javascript · CWE-502 | Yüksek8,1 | — | %3,0 | 1 Haz 2020 |
32İzleyin | CVE-2022-28376İstismar yok | Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, verizon · lvskihp firmware · CWE-287 | Yüksek8,1 | — | %1,2 | 3 Nis 2022 |
31İzleyin | CVE-2019-3916İstismar yok | Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated verizon · fios quantum gateway g1100 firmware · CWE-425 | Yüksek7,5 | — | %2,1 | 11 Nis 2019 |
30İzleyin | CVE-2022-29729İstismar yok | Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwordsverizon · 4g lte network extender firmware · CWE-521 | Yüksek7,5 | — | %1,5 | 2 Haz 2022 |
30İzleyin | CVE-2022-28377İstismar yok | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a stverizon · lvskihp indoorunit firmware · CWE-521 | Yüksek7,5 | — | %0,9 | 14 Tem 2022 |
30İzleyin | CVE-2022-28372İstismar yok | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a meverizon · lvskihp indoorunit firmware · CWE-434 | Yüksek7,5 | — | %0,7 | 14 Tem 2022 |
30İzleyin | CVE-2019-3915İstismar yok | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unautheverizon · fios quantum gateway g1100 firmware · CWE-294 | Yüksek7,5 | — | %0,6 | 11 Nis 2019 |
30İzleyin | CVE-2022-28371İstismar yok | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a stverizon · lvskihp indoorunit firmware · CWE-798 | Yüksek7,5 | — | %0,6 | 14 Tem 2022 |
30İzleyin | CVE-2022-28370İstismar yok | On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmwarverizon · lvskihp outdoorunit firmware · CWE-345 | Yüksek7,5 | — | %0,4 | 14 Tem 2022 |
28İzleyin | CVE-2013-0126Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.verizon · fios actiontec mi424wr-gen31 router firmware · CWE-352 | Orta6,8 | — | %2,9 | 21 Mar 2013 |
24İzleyin | CVE-2013-4875İstismar yok | The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot proverizon · wireless network extender · CWE-287 | Orta6,2 | — | %0,7 | 18 Tem 2013 |
24İzleyin | CVE-2013-4876İstismar yok | The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximateverizon · wireless network extender · CWE-255 | Orta6,2 | — | %0,7 | 18 Tem 2013 |
24İzleyin | CVE-2013-4874İstismar yok | The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by conneverizon · wireless network extender · CWE-287 | Orta6,2 | — | %0,7 | 18 Tem 2013 |
21İzleyin | CVE-2019-16769İstismar yok | Affected versions of serialize-javascript are vulnerable to Cross-site Scripting (XSS)verizon · serialize-javascript · CWE-79 | Orta5,4 | — | %0,8 | 5 Ara 2019 |
13İzleyin | CVE-2023-38301İstismar yok | An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers.CWE-200 | Düşük3,4 | — | %0,2 | 22 Nis 2024 |
10İzleyin | CVE-2013-4877İstismar yok | The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers toverizon · wireless network extender · CWE-287 | Düşük2,6 | — | %0,8 | 18 Tem 2013 |
- CVE-2022-2837540Planlayın
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile f
KritikCVSS 9,8İstismar yokEPSS %2verizon · lvskihp outdoorunit firmware14 Tem 2022
- CVE-2022-2837340Planlayın
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition funct
KritikCVSS 9,8İstismar yokEPSS %2verizon · lvskihp indoorunit firmware14 Tem 2022
- CVE-2022-2836939İzleyin
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-op
KritikCVSS 9,8İstismar yokEPSS %1verizon · lvskihp indoorunit firmware14 Tem 2022
- CVE-2019-391437İzleyin
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated a
YüksekCVSS 7,2İstismar yokEPSS %30verizon · fios quantum gateway g1100 firmware11 Nis 2019
- CVE-2022-2837436İzleyin
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Sett
YüksekCVSS 8,8İstismar yokEPSS %2verizon · lvskihp outdoorunit firmware14 Tem 2022
- CVE-2020-766033İzleyin
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
YüksekCVSS 8,1İstismar yokEPSS %3verizon · serialize-javascript1 Haz 2020
- CVE-2022-2837632İzleyin
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website,
YüksekCVSS 8,1İstismar yokEPSS %1verizon · lvskihp firmware3 Nis 2022
- CVE-2019-391631İzleyin
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated
YüksekCVSS 7,5İstismar yokEPSS %2verizon · fios quantum gateway g1100 firmware11 Nis 2019
- CVE-2022-2972930İzleyin
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords
YüksekCVSS 7,5İstismar yokEPSS %1verizon · 4g lte network extender firmware2 Haz 2022
- CVE-2022-2837730İzleyin
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a st
YüksekCVSS 7,5İstismar yokEPSS %1verizon · lvskihp indoorunit firmware14 Tem 2022
- CVE-2022-2837230İzleyin
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a me
YüksekCVSS 7,5İstismar yokEPSS %1verizon · lvskihp indoorunit firmware14 Tem 2022
- CVE-2019-391530İzleyin
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthe
YüksekCVSS 7,5İstismar yokEPSS %1verizon · fios quantum gateway g1100 firmware11 Nis 2019
- CVE-2022-2837130İzleyin
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a st
YüksekCVSS 7,5İstismar yokEPSS %1verizon · lvskihp indoorunit firmware14 Tem 2022
- CVE-2022-2837030İzleyin
On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmwar
YüksekCVSS 7,5İstismar yokEPSS %0verizon · lvskihp outdoorunit firmware14 Tem 2022
- CVE-2013-012628İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.
OrtaCVSS 6,8Kavram kanıtıEPSS %3verizon · fios actiontec mi424wr-gen31 router firmware21 Mar 2013
- CVE-2013-487524İzleyin
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot pro
OrtaCVSS 6,2İstismar yokEPSS %1verizon · wireless network extender18 Tem 2013
- CVE-2013-487624İzleyin
The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximate
OrtaCVSS 6,2İstismar yokEPSS %1verizon · wireless network extender18 Tem 2013
- CVE-2013-487424İzleyin
The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by conne
OrtaCVSS 6,2İstismar yokEPSS %1verizon · wireless network extender18 Tem 2013
- CVE-2019-1676921İzleyin
Affected versions of serialize-javascript are vulnerable to Cross-site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %1verizon · serialize-javascript5 Ara 2019
- CVE-2023-3830113İzleyin
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers.
DüşükCVSS 3,4İstismar yokEPSS %022 Nis 2024
- CVE-2013-487710İzleyin
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to
DüşükCVSS 2,6İstismar yokEPSS %1verizon · wireless network extender18 Tem 2013