Csaf
by Cisagov
Source repositories
CVEs (129)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55067 | Hig | 0.46 | 7.1 | 0.00 | Oct 23, 2025 | The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as… | ||
| CVE-2026-81305 | Med | 0.44 | 6.8 | 0.00 | Sep 18, 2026 | CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected… | ||
| CVE-2026-66372 | Med | 0.44 | 6.8 | 0.00 | Sep 15, 2026 | The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space. | ||
| CVE-2025-64770 | Med | 0.44 | 6.8 | 0.00 | Nov 20, 2025 | The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information. | ||
| CVE-2025-62674 | Med | 0.44 | 6.8 | 0.00 | Nov 20, 2025 | The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information. | ||
| CVE-2026-68953 | Med | 0.42 | 6.5 | 0.00 | Sep 15, 2026 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. | ||
| CVE-2026-77975 | Med | 0.42 | 6.5 | 0.00 | Aug 31, 2026 | The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use… | ||
| CVE-2026-66720 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during … | ||
| CVE-2026-66369 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,… | ||
| CVE-2026-66364 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,… | ||
| CVE-2026-66349 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing… | ||
| CVE-2026-65421 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition. | ||
| CVE-2026-63550 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position … | ||
| CVE-2026-56758 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2026 | The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer. | ||
| CVE-2026-44622 | Med | 0.42 | 6.5 | 0.00 | Jun 25, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-52866 | Med | 0.42 | 6.5 | 0.00 | Jun 19, 2026 | An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection. | ||
| CVE-2026-50034 | Med | 0.42 | 6.5 | 0.00 | Jun 19, 2026 | An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values. | ||
| CVE-2025-12636 | Med | 0.42 | 6.5 | 0.00 | Nov 6, 2025 | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of… | ||
| CVE-2026-21404 | Med | 0.41 | 6.3 | 0.00 | Jun 4, 2026 | NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful… | ||
| CVE-2026-35555 | Med | 0.41 | 6.3 | 0.00 | May 12, 2026 | PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups. |
- risk 0.46cvss 7.1epss 0.00
The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January 19, 2038, it resets to December 13, 1901, causing authentication failures and disrupting core system functionalities such as…
- risk 0.44cvss 6.8epss 0.00
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code in the security context of the affected…
- risk 0.44cvss 6.8epss 0.00
The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.
- risk 0.44cvss 6.8epss 0.00
The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.
- risk 0.44cvss 6.8epss 0.00
The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.
- risk 0.42cvss 6.5epss 0.00
The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.
- risk 0.42cvss 6.5epss 0.00
The affected Ebyte product exports administrative credentials and other sensitive configuration information without adequate protection. An unauthenticated attacker on the adjacent network who can obtain an exported configuration file could recover valid credentials and use…
- risk 0.42cvss 6.5epss 0.00
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during …
- risk 0.42cvss 6.5epss 0.00
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…
- risk 0.42cvss 6.5epss 0.00
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…
- risk 0.42cvss 6.5epss 0.00
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…
- risk 0.42cvss 6.5epss 0.00
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.
- risk 0.42cvss 6.5epss 0.00
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …
- risk 0.42cvss 6.5epss 0.00
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.
- risk 0.42cvss 6.5epss 0.00
An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.
- risk 0.42cvss 6.5epss 0.00
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of…
- risk 0.41cvss 6.3epss 0.00
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful…
- risk 0.41cvss 6.3epss 0.00
PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
Page 5 of 7