Xport Edge Firmware
by Lantronix
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-7237 | Med | 0.37 | 5.7 | 0.00 | Jan 23, 2024 | Lantronix XPort sends weakly encoded credentials within web request headers. | ||
| CVE-2020-13528 | Med | 0.35 | 5.3 | 0.03 | Dec 18, 2020 | An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger… | ||
| CVE-2020-13527 | Med | 0.29 | 4.5 | 0.01 | Dec 18, 2020 | An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this… |
- risk 0.37cvss 5.7epss 0.00
Lantronix XPort sends weakly encoded credentials within web request headers.
- risk 0.35cvss 5.3epss 0.03
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger…
- risk 0.29cvss 4.5epss 0.01
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this…