Page 3 of 42 results (0.005 seconds)

CVSS: 5.7EPSS: 0%CPEs: 36EXPL: 0

A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks. • https://cert.vde.com/en/advisories/VDE-2024-039 • CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer •

CVSS: 5.3EPSS: 0%CPEs: 36EXPL: 0

An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers. • https://cert.vde.com/en/advisories/VDE-2024-052 • CWE-770: Allocation of Resources Without Limits or Throttling •

CVSS: 8.6EPSS: 0%CPEs: 4EXPL: 0

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password. • https://cert.vde.com/en/advisories/VDE-2024-022 • CWE-1188: Initialization of a Resource with an Insecure Default •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Phoenix Contact CHARX SEC-3100 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firewall. The issue results from incorrect ordering and synchronization of services during startup. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. • https://cert.vde.com/en/advisories/VDE-2024-022 • CWE-552: Files or Directories Accessible to External Parties •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567. Posible desbordamiento del búfer en el manejo inseguro de variables UEFI en Phoenix SecureCore™ para Intel Gemini Lake. Este problema afecta a: SecureCore™ para Intel Gemini Lake: desde 4.1.0.1 anterior a 4.1.0.567. • https://www.phoenix.com/security-notifications/cve-2024-1598 • CWE-121: Stack-based Buffer Overflow •