Vulnerability index

Browse CVEs

135 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43386

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43387

A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASS…

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware HIGH 8.8
CVE-2024-43388

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

Fix: 8.9.3+
Fix from $1,950 2024-09-10
Tc Mguard Rs4000 4g Vzw Vpn Firmware MEDIUM 5.3
CVE-2024-7734

An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connecti…

Fix: 8.9.3+
Fix from $1,600 2024-09-10
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2024-6788

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, lo…

Fix: 1.6.3+
Fix from $2,300 2024-08-13
Charx Sec 3150 Firmware MEDIUM 5.9
CVE-2024-3913

An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system …

Fix: 1.6.3+
Fix from $1,600 2024-08-13
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-28137

A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-28136

A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCP…

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware MEDIUM 5.0
CVE-2024-28135

A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due t…

Fix: after 1.5.1
Fix from $1,600 2024-05-14
Charx Sec 3000 Firmware HIGH 7.0
CVE-2024-28134

An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the cur…

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-28133

A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. 

Fix: after 1.5.1
Fix from $1,950 2024-05-14
Charx Sec 3000 Firmware HIGH 8.7
CVE-2024-26288

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affect…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.5
CVE-2024-26003

An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. 

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.5
CVE-2024-26004

An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functio…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2024-26001

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not a…

Fix: 1.5.1+
Fix from $2,300 2024-03-12
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-25999

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. 

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.8
CVE-2024-26002

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of spec…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.5
CVE-2024-26000

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not al…

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware HIGH 7.3
CVE-2024-25998

An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

Fix: 1.5.1+
Fix from $1,950 2024-03-12
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2024-25995

An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper i…

Fix: 1.5.1+
Fix from $2,300 2024-03-12
Charx Sec 3000 Firmware CRITICAL 9.8
CVE-2024-25996

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

Fix: 1.5.1+
Fix from $2,300 2024-03-12
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2024-25994

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write …

Fix: 1.5.1+
Fix from $1,600 2024-03-12
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2024-25997

An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

Fix: 1.5.1+
Fix from $1,600 2024-03-12
Multiprog HIGH 7.5
CVE-2023-5592

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated re…

Mitigation only
Fix from $1,950 2023-12-14
Automationworx Software Suite HIGH 7.5
CVE-2023-46143

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some …

Mitigation only
Fix from $1,950 2023-12-14
Axc F 1152 Firmware MEDIUM 6.5
CVE-2023-46144

A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on…

Fix: after 2024.0
Fix from $1,600 2023-12-14
Multiprog CRITICAL 9.8
CVE-2023-0757

Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unaut…

Mitigation only
Fix from $2,300 2023-12-14
Automationworx Software Suite CRITICAL 9.8
CVE-2023-46141

Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthen…

Mitigation only
Fix from $2,300 2023-12-14
Axc F 1152 Firmware HIGH 8.8
CVE-2023-46142

A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full …

Fix: after 2024.0
Fix from $1,950 2023-12-14
Wp 6070 Wvps Firmware HIGH 8.8
CVE-2023-37861

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions wit…

Fix: 4.0.10+
Fix from $1,950 2023-08-09