VDE
by VDE
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25090 | Med | 0.35 | 5.4 | 0.00 | Mar 13, 2024 | An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability. | ||
| CVE-2024-25997 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected. | ||
| CVE-2024-25994 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. | ||
| CVE-2024-7734 | Med | 0.34 | 5.3 | 0.00 | Sep 10, 2024 | An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers. | ||
| CVE-2024-25996 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. | ||
| CVE-2022-45139 | Med | 0.34 | 5.3 | 0.00 | Feb 27, 2023 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a… | ||
| CVE-2024-28135 | Med | 0.33 | 5.0 | 0.01 | May 14, 2024 | A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected. |
- risk 0.35cvss 5.4epss 0.00
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.
- risk 0.35cvss 5.3epss 0.01
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.
- risk 0.34cvss 5.3epss 0.00
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic information pages on the webserver. In combination with CVE-2022-45138 this could lead to disclosure of device information like CPU diagnostics. As there is just a…
- risk 0.33cvss 5.0epss 0.01
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
Page 3 of 3