0.0

CVE-2024-7131 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 26, 2024, 2:02 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 11:15 p.m.

6.9

CVSS4.0

CVE-2024-6922 - Server-Side Request Forgery in Automation 360

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.

πŸ“… Published: July 26, 2024, 1:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2024-40689 - IBM InfoSphere Information Server SQL injection

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. IBM X-Force ID: 297719.

πŸ“… Published: July 26, 2024, 1:27 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

8.6

CVSS4.0

CVE-2024-41692 - Incorrect Access Control Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vul…

πŸ“… Published: July 26, 2024, 12:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-41691 - Insecure Storage of Sensitive Information Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary da…

πŸ“… Published: July 26, 2024, 12:06 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

7

CVSS4.0

CVE-2024-41690 - Default Credential Storage in Plaintext Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to acc…

πŸ“… Published: July 26, 2024, 12:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

5.2

CVSS4.0

CVE-2024-41689 - Hard-coded Credentials Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext WPA/…

πŸ“… Published: July 26, 2024, 11:59 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

7

CVSS4.0

CVE-2024-41688 - Cleartext Storage of Sensitive Information Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plai…

πŸ“… Published: July 26, 2024, 11:56 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

8.6

CVSS4.0

CVE-2024-41687 - Cleartext Transmission of Sensitive Information Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission within an HTTP session on the vulnerable system. Successful exploitation of this vulnerability could allow …

πŸ“… Published: July 26, 2024, 11:50 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

7.3

CVSS4.0

CVE-2024-41686 - Password Policy Bypass Vulnerability

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulner…

πŸ“… Published: July 26, 2024, 11:45 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.
Total resulsts: 349182
Page 9048 of 34,919
Β« previous page Β» next page
Filters