Security Vulnerabilities
- CVEs Published In February 2023
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
Libpeconv – access violation, before commit b076013 (30/11/2022).
Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).
Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
Media CP Media Control Panel latest version. Insufficiently protected credential change.
Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.