Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2023
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Incorrect Authorization vulnerability that could lead to a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.
CVSS Score
8.8
EPSS Score
0.011
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
CVSS Score
8.2
EPSS Score
0.003
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
CVSS Score
7.2
EPSS Score
0.003
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.
CVSS Score
7.2
EPSS Score
0.002
Published
2023-08-09
There is a command injection problem in the old version of the mobile phone backup app.
CVSS Score
7.4
EPSS Score
0.005
Published
2023-08-09
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.
CVSS Score
9.1
EPSS Score
0.004
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
CVSS Score
4.3
EPSS Score
0.001
Published
2023-08-09
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid session on the device.
CVSS Score
3.8
EPSS Score
0.001
Published
2023-08-09


Contact Us

Shodan ® - All rights reserved