7.5

CVSS3.1

CVE-2024-9579 - Certain Poly Video Conference Devices โ€“ Potential Remote Code Execution

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.

๐Ÿ“… Published: Nov. 5, 2024, 4:22 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 6:08 p.m.

4.2

CVSS3.1

CVE-2023-29126 - Insecure loose comparison in Enel X JuiceBox

The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.

๐Ÿ“… Published: Nov. 5, 2024, 3:28 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:15 p.m.

9

CVSS3.1

CVE-2023-29125 - Heap overflow in CM_main.exe binary in Enel X JuiceBox

A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.

๐Ÿ“… Published: Nov. 5, 2024, 3:27 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:10 p.m.

6.7

CVSS3.1

CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox

Under certain conditions, access to service libraries is granted to account they should not have access to.

๐Ÿ“… Published: Nov. 5, 2024, 3:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox

Waybox Enel TCF Agent service could be used to get administratorโ€™s privileges over the Waybox system.

๐Ÿ“… Published: Nov. 5, 2024, 3:23 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administratorโ€™s privileges over the Waybox system.

๐Ÿ“… Published: Nov. 5, 2024, 3:22 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29119 - Unauthorized SQLite Injection

Waybox Enel X web management application could execute arbitrary requests on the internal database viaย /admin/dbstore.php.

๐Ÿ“… Published: Nov. 5, 2024, 3:20 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29118 - Unauthorized SQLite Injection in Enel X Juicebox

Waybox Enel X web management application could execute arbitrary requests on the internal database viaย /admin/versions.php.

๐Ÿ“… Published: Nov. 5, 2024, 3:18 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:08 p.m.

8.8

CVSS3.1

CVE-2023-29117 - Authentication Bypass in JuiceBox Web Manager interface

Waybox Enel X web management API authentication could be bypassed and provide administratorโ€™s privileges over the Waybox system.

๐Ÿ“… Published: Nov. 5, 2024, 3:14 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:08 p.m.

4.3

CVSS3.1

CVE-2023-29116 - PHP Information Disclosure in Enel X JuiceBox

Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.

๐Ÿ“… Published: Nov. 5, 2024, 3:08 p.m. ๐Ÿ”„ Last Modified: Nov. 8, 2024, 4:08 p.m.
Total resulsts: 346569
Page 7752 of 34,657
ยซ previous page ยป next page
Filters