Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2023
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVSS Score
6.7
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
CVSS Score
6.7
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-02-12
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
CVSS Score
7.0
EPSS Score
0.001
Published
2023-02-12
IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string attack. IBM X-Force ID: 239539.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-02-12


Contact Us

Shodan ® - All rights reserved