CVE-2024-5422 – Denial of Service
https://notcve.org/view.php?id=CVE-2024-5422
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below. Un consumo incontrolado de recursos de descriptores de archivos en SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 permite DoS a través de HTTP. Este problema afecta a utnserver Pro, utnserver ProMAX, INU-100 versión 20.1.22 y versiones anteriores. SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-5421 – Authenticated Command Injection
https://notcve.org/view.php?id=CVE-2024-5421
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below. Falta la validación de entrada y la integración de comandos del sistema operativo de la entrada en utnserver Pro, utnserver ProMAX, la interfaz web INU-100 permite la inyección de comandos autenticados. Este problema afecta a utnserver Pro, utnserver ProMAX, INU-100 versión 20.1.22 y versiones anteriores. SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2024-5420 – Stored Cross-Site Scripting in SEH Computertechnik utnserver Pro
https://notcve.org/view.php?id=CVE-2024-5420
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below. Falta la validación de entrada en SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, la interfaz web de SEH Computertechnik INU-100 permite Cross-Site Scripting (XSS) Almacenado. Este problema afecta a utnserver Pro, utnserver ProMAX, INU-100 versión 20.1.22. y por debajo. SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • https://github.com/fa-rrel/CVE-2024-5420-XSS http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-oring-iap420/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •