diff --git a/advisories/unreviewed/2022/05/GHSA-57rv-qg24-x8hj/GHSA-57rv-qg24-x8hj.json b/advisories/unreviewed/2022/05/GHSA-57rv-qg24-x8hj/GHSA-57rv-qg24-x8hj.json index 610799c1eca..32a4ded4b7f 100644 --- a/advisories/unreviewed/2022/05/GHSA-57rv-qg24-x8hj/GHSA-57rv-qg24-x8hj.json +++ b/advisories/unreviewed/2022/05/GHSA-57rv-qg24-x8hj/GHSA-57rv-qg24-x8hj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57rv-qg24-x8hj", - "modified": "2022-05-24T19:05:03Z", + "modified": "2024-11-24T15:31:37Z", "published": "2022-05-24T19:05:03Z", "aliases": [ "CVE-2021-22764" ], "details": "A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -18,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22764" }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-159-02.pdf" + }, + { + "type": "WEB", + "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02%2Chttp://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03" + }, { "type": "WEB", "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02,http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03" diff --git a/advisories/unreviewed/2022/05/GHSA-xj35-rhxx-w86c/GHSA-xj35-rhxx-w86c.json b/advisories/unreviewed/2022/05/GHSA-xj35-rhxx-w86c/GHSA-xj35-rhxx-w86c.json index 8c83496b7d2..0fd269dbb5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-xj35-rhxx-w86c/GHSA-xj35-rhxx-w86c.json +++ b/advisories/unreviewed/2022/05/GHSA-xj35-rhxx-w86c/GHSA-xj35-rhxx-w86c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xj35-rhxx-w86c", - "modified": "2022-05-24T19:05:03Z", + "modified": "2024-11-24T15:31:37Z", "published": "2022-05-24T19:05:03Z", "aliases": [ "CVE-2021-22763" ], "details": "A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22763" }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-159-02.pdf" + }, + { + "type": "WEB", + "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02%2Chttp://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03" + }, { "type": "WEB", "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02,http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03" diff --git a/advisories/unreviewed/2024/11/GHSA-7932-gcjg-wrfw/GHSA-7932-gcjg-wrfw.json b/advisories/unreviewed/2024/11/GHSA-7932-gcjg-wrfw/GHSA-7932-gcjg-wrfw.json index 2d7cd3e47f4..c9cc8e68fa3 100644 --- a/advisories/unreviewed/2024/11/GHSA-7932-gcjg-wrfw/GHSA-7932-gcjg-wrfw.json +++ b/advisories/unreviewed/2024/11/GHSA-7932-gcjg-wrfw/GHSA-7932-gcjg-wrfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7932-gcjg-wrfw", - "modified": "2024-11-11T09:30:42Z", + "modified": "2024-11-24T15:31:38Z", "published": "2024-11-11T09:30:42Z", "aliases": [ "CVE-2024-11068" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11068" }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-bug-in-60-000-exposed-eol-modems" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/en/cp-139-8234-0514c-2.html" diff --git a/advisories/unreviewed/2024/11/GHSA-9fqj-q497-4x32/GHSA-9fqj-q497-4x32.json b/advisories/unreviewed/2024/11/GHSA-9fqj-q497-4x32/GHSA-9fqj-q497-4x32.json index 347b2121846..358233bf6b0 100644 --- a/advisories/unreviewed/2024/11/GHSA-9fqj-q497-4x32/GHSA-9fqj-q497-4x32.json +++ b/advisories/unreviewed/2024/11/GHSA-9fqj-q497-4x32/GHSA-9fqj-q497-4x32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9fqj-q497-4x32", - "modified": "2024-11-11T09:30:42Z", + "modified": "2024-11-24T15:31:38Z", "published": "2024-11-11T09:30:42Z", "aliases": [ "CVE-2024-11066" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11066" }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-bug-in-60-000-exposed-eol-modems" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/en/cp-139-8232-5d94e-2.html" diff --git a/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json index 2a3557d66f6..614b9af54fa 100644 --- a/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json +++ b/advisories/unreviewed/2024/11/GHSA-cgvw-jh5j-mgq3/GHSA-cgvw-jh5j-mgq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvw-jh5j-mgq3", - "modified": "2024-11-19T18:30:59Z", + "modified": "2024-11-24T15:31:38Z", "published": "2024-11-18T18:30:58Z", "aliases": [ "CVE-2024-9474" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2024-9474" + }, + { + "type": "WEB", + "url": "https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-f3qc-f3rx-3hrm/GHSA-f3qc-f3rx-3hrm.json b/advisories/unreviewed/2024/11/GHSA-f3qc-f3rx-3hrm/GHSA-f3qc-f3rx-3hrm.json index ecbf3b7b9e2..be503cae464 100644 --- a/advisories/unreviewed/2024/11/GHSA-f3qc-f3rx-3hrm/GHSA-f3qc-f3rx-3hrm.json +++ b/advisories/unreviewed/2024/11/GHSA-f3qc-f3rx-3hrm/GHSA-f3qc-f3rx-3hrm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3qc-f3rx-3hrm", - "modified": "2024-11-11T09:30:42Z", + "modified": "2024-11-24T15:31:38Z", "published": "2024-11-11T09:30:42Z", "aliases": [ "CVE-2024-11067" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11067" }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-bug-in-60-000-exposed-eol-modems" + }, { "type": "WEB", "url": "https://www.twcert.org.tw/en/cp-139-8233-903d9-2.html" diff --git a/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json index 9ef1cf1ce2b..442126b1519 100644 --- a/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json +++ b/advisories/unreviewed/2024/11/GHSA-mw9x-2qwv-599p/GHSA-mw9x-2qwv-599p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw9x-2qwv-599p", - "modified": "2024-11-19T18:30:59Z", + "modified": "2024-11-24T15:31:38Z", "published": "2024-11-18T18:30:58Z", "aliases": [ "CVE-2024-0012" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2024-0012" + }, + { + "type": "WEB", + "url": "https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json b/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json index dbb26c50a8a..7bca5129475 100644 --- a/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json +++ b/advisories/unreviewed/2024/11/GHSA-qp96-9hxv-3xx4/GHSA-qp96-9hxv-3xx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp96-9hxv-3xx4", - "modified": "2024-11-06T15:30:40Z", + "modified": "2024-11-24T15:31:37Z", "published": "2024-11-06T15:30:40Z", "aliases": [ "CVE-2024-10914" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://vuldb.com/?submit.432847" }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices" + }, { "type": "WEB", "url": "https://www.dlink.com" @@ -48,7 +52,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-707" + "CWE-707", + "CWE-74" ], "severity": "CRITICAL", "github_reviewed": false,