Aggregator
CVE-2024-46888 | Siemens SINEC INS up to 1.0 SP2 Update 2 SFTP path traversal (ssa-915275)
9 months 2 weeks ago
A vulnerability was found in Siemens SINEC INS up to 1.0 SP2 Update 2. It has been declared as critical. This vulnerability affects unknown code of the component SFTP. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-46888. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-46890 | Siemens SINEC INS up to 1.0 SP2 Update 2 os command injection (ssa-915275)
9 months 2 weeks ago
A vulnerability classified as critical was found in Siemens SINEC INS up to 1.0 SP2 Update 2. Affected by this vulnerability is an unknown functionality. The manipulation leads to os command injection.
This vulnerability is known as CVE-2024-46890. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-46889 | Siemens SINEC INS up to 1.0 SP2 Update 2 Configuration File hard-coded key (ssa-915275)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Siemens SINEC INS up to 1.0 SP2 Update 2. This affects an unknown part of the component Configuration File Handler. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is uniquely identified as CVE-2024-46889. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-46892 | Siemens SINEC INS up to 1.0 SP2 Update 2 session expiration (ssa-915275)
9 months 2 weeks ago
A vulnerability has been found in Siemens SINEC INS up to 1.0 SP2 Update 2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to session expiration.
This vulnerability was named CVE-2024-46892. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47808 | Siemens SINEC NMS up to 3.0 permission assignment (ssa-331112)
9 months 2 weeks ago
A vulnerability was found in Siemens SINEC NMS up to 3.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to incorrect permission assignment.
This vulnerability is handled as CVE-2024-47808. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47940 | Siemens Solid Edge SE2024 up to 224.0 Update 8 PSM File out-of-bounds (ssa-351178)
9 months 2 weeks ago
A vulnerability was found in Siemens Solid Edge SE2024 up to 224.0 Update 8. It has been classified as critical. This affects an unknown part of the component PSM File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2024-47940. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47941 | Siemens Solid Edge SE2024 up to 224.0 Update 8 PAR File out-of-bounds (ssa-351178)
9 months 2 weeks ago
A vulnerability was found in Siemens Solid Edge SE2024 up to 224.0 Update 8. It has been declared as critical. This vulnerability affects unknown code of the component PAR File Handler. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-47941. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47783 | Siemens SIPORT up to 3.3.x Installation Folder permission assignment (ssa-064257)
9 months 2 weeks ago
A vulnerability was found in Siemens SIPORT up to 3.3.x. It has been rated as critical. This issue affects some unknown processing of the component Installation Folder. The manipulation leads to incorrect permission assignment.
The identification of this vulnerability is CVE-2024-47783. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11061 | Tenda AC10 16.03.10.13 fast_setting_wifi_set FUN_0044db3c timeZone stack-based overflow
9 months 2 weeks ago
A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function FUN_0044db3c of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-11061. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-11058 | CodeAstro Real Estate Management System up to 1.0 About Us Page /aboutedit.php id sql injection
9 months 2 weeks ago
A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-11058. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
NickStick Design Releases the RF PowerSnitch USB-C Version
9 months 2 weeks ago
November 14, 2024Recent
DataCon2024 | 比赛第二日成绩速报
9 months 2 weeks ago
DataCon2024赛况速报
APT-C-55(Kimsuky)组织利用GitHub作为载荷平台的攻击活动分析
9 months 2 weeks ago
Kimsuky组织采纳了一种新颖策略,即利用GitHub作为恶意载荷的分发平台,以此实现信息窃取等恶意行为
APT-C-55(Kimsuky)组织利用GitHub作为载荷平台的攻击活动分析
9 months 2 weeks ago
Kimsuky组织采纳了一种新颖策略,即利用GitHub作为恶意载荷的分发平台,以此实现信息窃取等恶意行为
又一产业学院揭牌!三方携手共育实战型网络安全人才
9 months 2 weeks ago
360携手山东交通学院、山东人才发展集团,共建现代产业学院
360与云南电信战略携手,共铸“两亚信息大通道”安全基石
9 months 2 weeks ago
360与云南电信签约 为全国出海企业提供安全服务
微软宣布 .NET 9
9 months 2 weeks ago
微软宣布了 .NET 9,称新版本显著改进了性能,逾千项变更与性能相关。另一个重要变化当然是围绕目前炙手可热的 AI。.NET 9 的主要变化包括:Server GC 改进,Dynamic Profile Guided Optimization(PGO)能优化更多代码模式,LINQ 优化, .NET Aspire 9,在 Microsoft.Extensions.AI 和 Microsoft.Extensions.VectorData 下引入一组抽象提供统一的 C# 抽象层用于与 AI 服务交互,增强了 GitHub Copilot 整合,ASP.NET Core 优化了静态文件处理,改进了 Blazor 等等。
30 位科技圈牛人的 2025 工作计划,我们拿到了!
9 months 2 weeks ago
创新大会 2025 来了!早鸟限时六折优惠,先到先得!
The Magic ITAM Formula for Navigating Oracle Java Licensing
9 months 2 weeks ago
IT asset managers have their hands full when they’re trying to strike the best path forward for their companies’ use of Java. Finance leaders at many companies are turning to ITAM professionals and asking them to reduce the cost of Java with a magic ITAM formula. Azul Vice President of Worldwide Channel Sales Simon Taylor […]
The post The Magic ITAM Formula for Navigating Oracle Java Licensing appeared first on Azul | Better Java Performance, Superior Java Support.
The post The Magic ITAM Formula for Navigating Oracle Java Licensing appeared first on Security Boulevard.
Azul