CVE tracker
322 subscribers
4.53K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-2724 - GNOME libgsf Out-of-Bounds Read Vulnerability

CVE ID : CVE-2025-2724
Published : March 25, 2025, 2:15 a.m. | 3 hours, 42 minutes ago
Description : A vulnerability classified as problematic has been found in GNOME libgsf up to 1.14.53. Affected is the function sorting_key_copy. The manipulation of the argument Name leads to out-of-bounds read. It is possible to launch the attack on the local host. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2725 - H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 HTTP POST Request Handler Command Injection

CVE ID : CVE-2025-2725
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2726 - H3C Magic Series HTTP POST Request Handler Command Injection

CVE ID : CVE-2025-2726
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2727 - H3C Magic NX30 Pro HTTP POST Request Handler Command Injection

CVE ID : CVE-2025-2727
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2728 - H3C Magic NX30 Pro/Magic NX400 Command Injection Vulnerability

CVE ID : CVE-2025-2728
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2729 - H3C Magic Series HTTP POST Request Handler Command Injection Vulnerability

CVE ID : CVE-2025-2729
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2730 - H3C Magic Series HTTP POST Request Handler Command Injection Vulnerability

CVE ID : CVE-2025-2730
Published : March 25, 2025, 3:15 a.m. | 2 hours, 42 minutes ago
Description : A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2731 - H3C Magic Series HTTP POST Request Handler Command Injection Vulnerability

CVE ID : CVE-2025-2731
Published : March 25, 2025, 4:15 a.m. | 1 hour, 42 minutes ago
Description : A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-2732 - H3C Magic Series HTTP POST Request Handler Command Injection Vulnerability

CVE ID : CVE-2025-2732
Published : March 25, 2025, 4:15 a.m. | 1 hour, 42 minutes ago
Description : A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-10206 - B&R APROL SSRF

CVE ID : CVE-2024-10206
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL &LT4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-10207 - B&R APROL Server-Side Request Forgery (SSRF)

CVE ID : CVE-2024-10207
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL &LT4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-10208 - B&R APROL Cross-Site Scripting (XSS)

CVE ID : CVE-2024-10208
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL &LT4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-10209 - B&R APROL File System Incorrect Permission Assignment Vulnerability

CVE ID : CVE-2024-10209
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL &LT4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45480 - B&R APROL Code Injection Vulnerability

CVE ID : CVE-2024-45480
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL &LT4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45481 - B&R APROL SSH Server Authentication Bypass

CVE ID : CVE-2024-45481
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL &LT4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45482 - B&R APROL SSH Server Untrusted Control Sphere Command Injection

CVE ID : CVE-2024-45482
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL &LT4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45483 - B&R APROL Missing Authentication for Boot Configuration

CVE ID : CVE-2024-45483
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL &LT4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-45484 - B&R APROL Denial-of-Service (DoS) Allocation of Resources Without Limits

CVE ID : CVE-2024-45484
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL &LT4.4-00P5 may allow an unauthenticated adjacent attacker to per-form Denial-of-Service (DoS) attacks against the product.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-8313 - B&R APROL SNMP Sensitive Information Disclosure and Default Resource Initialization Vulnerability

CVE ID : CVE-2024-8313
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL &LT4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-8314 - B&R APROL Session Hijacking Vulnerability

CVE ID : CVE-2024-8314
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL &LT4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-8315 - B&R APROL Privilege Escalation Vulnerability

CVE ID : CVE-2024-8315
Published : March 25, 2025, 5:15 a.m. | 42 minutes ago
Description : An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL &LT4.4-00P5 may allow an authenticated local attacker to read credential information.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...