Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2024
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVSS Score
6.1
EPSS Score
0.005
Published
2024-09-04
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS Score
5.5
EPSS Score
0.001
Published
2024-09-04
Vulnerability of resources not being closed or released in the keystore module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
4.0
EPSS Score
0.001
Published
2024-09-04
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
5.1
EPSS Score
0.002
Published
2024-09-04
Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS Score
4.0
EPSS Score
0.002
Published
2024-09-04
Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS Score
4.3
EPSS Score
0.002
Published
2024-09-04
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.
CVSS Score
6.2
EPSS Score
0.002
Published
2024-09-04
Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able to manipulate and/or suspend the PLC and Operator Interfaces by accessing or hijacking them.
CVSS Score
8.1
EPSS Score
0.004
Published
2024-09-04
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated.
CVSS Score
4.6
EPSS Score
0.002
Published
2024-09-04
Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.005
Published
2024-09-03


Contact Us

Shodan ® - All rights reserved