From 024c86ca6970acbafbb56b981be99873329a71cf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 18 Sep 2024 12:32:58 +0000 Subject: [PATCH] Publish Advisories GHSA-46cp-m7j2-3fh7 GHSA-824r-f6r2-rhhx GHSA-9p5p-94m7-4mp9 GHSA-m58v-fvm4-hcrr GHSA-pq3c-jxwh-2qw9 GHSA-vvxm-2vxq-rhgq --- .../GHSA-46cp-m7j2-3fh7.json | 38 +++++++++++++++++++ .../GHSA-824r-f6r2-rhhx.json | 38 +++++++++++++++++++ .../GHSA-9p5p-94m7-4mp9.json | 38 +++++++++++++++++++ .../GHSA-m58v-fvm4-hcrr.json | 38 +++++++++++++++++++ .../GHSA-pq3c-jxwh-2qw9.json | 38 +++++++++++++++++++ .../GHSA-vvxm-2vxq-rhgq.json | 38 +++++++++++++++++++ 6 files changed, 228 insertions(+) create mode 100644 advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-824r-f6r2-rhhx/GHSA-824r-f6r2-rhhx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-9p5p-94m7-4mp9/GHSA-9p5p-94m7-4mp9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pq3c-jxwh-2qw9/GHSA-pq3c-jxwh-2qw9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json diff --git a/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json b/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json new file mode 100644 index 00000000000..56ad0332c2c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-46cp-m7j2-3fh7/GHSA-46cp-m7j2-3fh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46cp-m7j2-3fh7", + "modified": "2024-09-18T12:31:32Z", + "published": "2024-09-18T12:31:32Z", + "aliases": [ + "CVE-2024-6406" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Yordam Information Technology Mobile Library Application allows Retrieve Embedded Sensitive Data.This issue affects Mobile Library Application: before 5.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6406" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-824r-f6r2-rhhx/GHSA-824r-f6r2-rhhx.json b/advisories/unreviewed/2024/09/GHSA-824r-f6r2-rhhx/GHSA-824r-f6r2-rhhx.json new file mode 100644 index 00000000000..d41b41e6e55 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-824r-f6r2-rhhx/GHSA-824r-f6r2-rhhx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-824r-f6r2-rhhx", + "modified": "2024-09-18T12:31:31Z", + "published": "2024-09-18T12:31:31Z", + "aliases": [ + "CVE-2024-8887" + ], + "details": "CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8887" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-9p5p-94m7-4mp9/GHSA-9p5p-94m7-4mp9.json b/advisories/unreviewed/2024/09/GHSA-9p5p-94m7-4mp9/GHSA-9p5p-94m7-4mp9.json new file mode 100644 index 00000000000..cb6373bee46 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-9p5p-94m7-4mp9/GHSA-9p5p-94m7-4mp9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9p5p-94m7-4mp9", + "modified": "2024-09-18T12:31:32Z", + "published": "2024-09-18T12:31:32Z", + "aliases": [ + "CVE-2024-8888" + ], + "details": "An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods such as network captures, locally stored web information, etc.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8888" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json b/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json new file mode 100644 index 00000000000..38e0a693e7c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m58v-fvm4-hcrr/GHSA-m58v-fvm4-hcrr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m58v-fvm4-hcrr", + "modified": "2024-09-18T12:31:31Z", + "published": "2024-09-18T12:31:31Z", + "aliases": [ + "CVE-2024-43188" + ], + "details": "IBM Business Automation Workflow \n\n22.0.2, 23.0.1, 23.0.2, and 24.0.0\n\ncould allow a privileged user to perform unauthorized activities due to improper client side validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43188" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7168769" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pq3c-jxwh-2qw9/GHSA-pq3c-jxwh-2qw9.json b/advisories/unreviewed/2024/09/GHSA-pq3c-jxwh-2qw9/GHSA-pq3c-jxwh-2qw9.json new file mode 100644 index 00000000000..e40e117a96c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pq3c-jxwh-2qw9/GHSA-pq3c-jxwh-2qw9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq3c-jxwh-2qw9", + "modified": "2024-09-18T12:31:32Z", + "published": "2024-09-18T12:31:32Z", + "aliases": [ + "CVE-2024-8889" + ], + "details": "Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8889" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-circutor-products" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T12:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json new file mode 100644 index 00000000000..2b7076c23a9 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vvxm-2vxq-rhgq/GHSA-vvxm-2vxq-rhgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvxm-2vxq-rhgq", + "modified": "2024-09-18T12:31:31Z", + "published": "2024-09-18T12:31:31Z", + "aliases": [ + "CVE-2024-5682" + ], + "details": "Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation.This issue affects Yordam Library Automation System: before 20.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5682" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-18T12:15:03Z" + } +} \ No newline at end of file