VYPR

RELY-PCIe

by Relyum

CVEs (10)

  • CVE-2023-47577CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

  • CVE-2024-44574HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

  • CVE-2024-44572HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.01

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

  • CVE-2023-47578HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.00

    Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface.

  • CVE-2023-47576HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

  • CVE-2023-47573HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.

  • CVE-2023-47579HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.

  • CVE-2023-47575MedDec 13, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices are susceptible to reflected XSS.

  • CVE-2023-47574MedDec 13, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. There is a Weak SMB configuration with signing disabled.

  • CVE-2024-44573MedSep 11, 2024
    risk 0.31cvss 4.7epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.