Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2022
There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-09-20
The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to execute blind Server Side Request Forgery (SSRF) on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 12.0.0 and TIBCO Spotfire Server: version 12.0.0.
CVSS Score
7.1
EPSS Score
0.002
Published
2022-09-20
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
CVSS Score
7.5
EPSS Score
0.05
Published
2022-09-20
A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory. This issue affects: Module name: PlatformInitAdvancedPreMem SHA256: 644044fdb8daea30a7820e0f5f88dbf5cd460af72fbf70418e9d2e47efed8d9b Module GUID: EEEE611D-F78F-4FB9-B868-55907F169280 This issue affects: AMI Aptio 5.x.
CVSS Score
8.2
EPSS Score
0.0
Published
2022-09-20
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
CVSS Score
8.8
EPSS Score
0.005
Published
2022-09-20
A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-09-20
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-09-20
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.
CVSS Score
9.1
EPSS Score
0.003
Published
2022-09-20
An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the CRC check. A successful attack can either introduce a backdoor to the device or make the device DoS. This affects Firmware Version: 1.1.1_1.1.9.
CVSS Score
7.5
EPSS Score
0.0
Published
2022-09-20
An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to replace the user-uploaded firmware image with an original old firmware image. This affects Firmware 1.1.1_1.1.9 and earlier.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-09-20


Contact Us

Shodan ® - All rights reserved