VR-S1000
by Buffalotech
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46681 | Hig | 0.51 | 7.8 | 0.00 | Dec 26, 2023 | Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command. | ||
| CVE-2023-45741 | Med | 0.44 | 6.8 | 0.00 | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands. | ||
| CVE-2023-51363 | Med | 0.42 | 6.5 | 0.00 | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information. | ||
| CVE-2023-46711 | Med | 0.30 | 4.6 | 0.00 | Dec 26, 2023 | VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user. |
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.
- risk 0.44cvss 6.8epss 0.00
VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.
- risk 0.42cvss 6.5epss 0.00
VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.
- risk 0.30cvss 4.6epss 0.00
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.