CVE-2021-3986 – Information Disclosure in janeczku/calibre-web
https://notcve.org/view.php?id=CVE-2021-3986
This vulnerability discloses private information and affects all versions prior to the fix. • https://github.com/janeczku/calibre-web/commit/6f5390ead5df9779ac81fadefffb476e03f93548 https://huntr.com/bounties/394af194-61a7-4e33-b373-877d4c766fca • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2024-46383
https://notcve.org/view.php?id=CVE-2024-46383
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext. • http://skyworth.com https://github.com/nitinronge91/Sensitive-Information-disclosure-via-SPI-flash-firmware-for-Hathway-router-CVE-2024-46383 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2017-13227
https://notcve.org/view.php?id=CVE-2017-13227
This could lead to information disclosure with no additional execution privileges needed. • https://source.android.com/security/bulletin/2018-06-01 •
CVE-2024-48967 – Life2000 ventilator and Service PC lack sufficient audit logging capabilities
https://notcve.org/view.php?id=CVE-2024-48967
An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01 • CWE-778: Insufficient Logging •
CVE-2024-48966 – Life2000 service tools for test and calibration do not support user authentication
https://notcve.org/view.php?id=CVE-2024-48966
An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the calibration tool, without having to authenticate to either tool. This could result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01 • CWE-306: Missing Authentication for Critical Function •