Vendor
Vuforia
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29502 | Med | 0.40 | 6.2 | 0.01 | Jun 7, 2023 | Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path. | ||
| CVE-2023-29152 | Med | 0.40 | 6.2 | 0.00 | Jun 7, 2023 | By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account. | ||
| CVE-2023-29168 | Low | 0.24 | 3.7 | 0.00 | Jun 7, 2023 | The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication. |
- risk 0.40cvss 6.2epss 0.01
Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.json file to be a different path.
- risk 0.40cvss 6.2epss 0.00
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
- risk 0.24cvss 3.7epss 0.00
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.