
CVE-2019-7272 – Optergy 2.3.0a - Username Disclosure
https://notcve.org/view.php?id=CVE-2019-7272
01 Jul 2019 — Optergy Proton/Enterprise devices allow Username Disclosure. Los dispositivos Optergy Proton/Enterprise permiten la divulgación del nombre de usuario. • https://packetstorm.news/files/id/155259 • CWE-862: Missing Authorization •

CVE-2019-7273 – Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
https://notcve.org/view.php?id=CVE-2019-7273
01 Jul 2019 — Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). Los dispositivos Optergy Proton/Enterprise permiten Cross-Site Request Forgery (CSRF). Optergy Proton/Enterprise BMS versions 2.0.3a and below suffer from an add administrator cross site request forgery vulnerability. • https://packetstorm.news/files/id/155265 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2019-7274 – Optergy 2.3.0a - Remote Code Execution
https://notcve.org/view.php?id=CVE-2019-7274
01 Jul 2019 — Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root. Los dispositivos Optergy Proton / Enterprise permiten la carga de archivos autenticados con la ejecución de código como root. • https://packetstorm.news/files/id/155269 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2019-7275 – Optergy Proton/Enterprise BMS 2.3.0a Open Redirect
https://notcve.org/view.php?id=CVE-2019-7275
01 Jul 2019 — Optergy Proton/Enterprise devices allow Open Redirect. Los dispositivos Optergy Proton/Enterprise permiten una redirección abierta. Optergy Proton/Enterprise BMS versions 2.3.0a and below suffer from an open redirect vulnerability. • https://packetstorm.news/files/id/155268 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2019-7277
https://notcve.org/view.php?id=CVE-2019-7277
01 Jul 2019 — Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure. Los dispositivos Optergy Proton/Enterprise permiten la divulgación de información de red interna no autenticada. • http://www.securityfocus.com/bid/108686 •

CVE-2019-7278
https://notcve.org/view.php?id=CVE-2019-7278
01 Jul 2019 — Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service. Los dispositivos Optergy Proton/Enterprise tienen un servicio de envío de SMS no autenticado. • http://www.securityfocus.com/bid/108686 • CWE-269: Improper Privilege Management •

CVE-2019-7279
https://notcve.org/view.php?id=CVE-2019-7279
01 Jul 2019 — Optergy Proton/Enterprise devices have Hard-coded Credentials. Los dispositivos Optergy Proton/Enterprise tienen credenciales codificadas. • http://www.securityfocus.com/bid/108686 • CWE-798: Use of Hard-coded Credentials •

CVE-2019-7276 – Optergy Proton and Enterprise BMS Command Injection using a backdoor
https://notcve.org/view.php?id=CVE-2019-7276
01 Jul 2019 — Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. Los dispositivos Optergy Proton/Enterprise permiten la ejecución remota de código raíz a través de una consola Backdoor. • https://packetstorm.news/files/id/171564 •