7.5
CVE-2024-9579 - Certain Poly Video Conference Devices โ Potential Remote Code Execution
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
4.2
CVE-2023-29126 - Insecure loose comparison in Enel X JuiceBox
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
9
CVE-2023-29125 - Heap overflow in CM_main.exe binary in Enel X JuiceBox
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
6.7
CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
Under certain conditions, access to service libraries is granted to account they should not have access to.
9.6
CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox
Waybox Enel TCF Agent service could be used to get administratorโs privileges over the Waybox system.
9.6
CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administratorโs privileges over the Waybox system.
9.6
CVE-2023-29119 - Unauthorized SQLite Injection
Waybox Enel X web management application could execute arbitrary requests on the internal database viaย /admin/dbstore.php.
9.6
CVE-2023-29118 - Unauthorized SQLite Injection in Enel X Juicebox
Waybox Enel X web management application could execute arbitrary requests on the internal database viaย /admin/versions.php.
8.8
CVE-2023-29117 - Authentication Bypass in JuiceBox Web Manager interface
Waybox Enel X web management API authentication could be bypassed and provide administratorโs privileges over the Waybox system.
4.3
CVE-2023-29116 - PHP Information Disclosure in Enel X JuiceBox
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.