diff --git a/advisories/unreviewed/2024/03/GHSA-3mq7-j5f9-79xq/GHSA-3mq7-j5f9-79xq.json b/advisories/unreviewed/2024/03/GHSA-3mq7-j5f9-79xq/GHSA-3mq7-j5f9-79xq.json new file mode 100644 index 00000000000..f04755b0b1a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3mq7-j5f9-79xq/GHSA-3mq7-j5f9-79xq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mq7-j5f9-79xq", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-2425" + ], + "details": "\nA denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2425" + }, + { + "type": "WEB", + "url": "https://https://www.rockwellautomation.com/en-us/support/advisory.SD1664.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-7qfp-8qgp-4xc8/GHSA-7qfp-8qgp-4xc8.json b/advisories/unreviewed/2024/03/GHSA-7qfp-8qgp-4xc8/GHSA-7qfp-8qgp-4xc8.json new file mode 100644 index 00000000000..6f82e99e44e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-7qfp-8qgp-4xc8/GHSA-7qfp-8qgp-4xc8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qfp-8qgp-4xc8", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-2427" + ], + "details": "\nA denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to the device repeatedly the device will crash and require a manual restart to recover.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2427" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1664.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-chvg-xhgp-pg84/GHSA-chvg-xhgp-pg84.json b/advisories/unreviewed/2024/03/GHSA-chvg-xhgp-pg84/GHSA-chvg-xhgp-pg84.json new file mode 100644 index 00000000000..4673fe97e60 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-chvg-xhgp-pg84/GHSA-chvg-xhgp-pg84.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chvg-xhgp-pg84", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-29440" + ], + "details": "An unauthorized access vulnerability has been discovered in ROS2 Humble Hawksbill versions where ROS_VERSION is 2 and ROS_PYTHON_VERSION is 3. This vulnerability could potentially allow a malicious user to gain unauthorized access to multiple ROS2 nodes remotely. Unauthorized access to these nodes could result in compromised system integrity, the execution of arbitrary commands, and disclosure of sensitive information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29440" + }, + { + "type": "WEB", + "url": "https://github.com/yashpatelphd/CVE-2024-29440" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json b/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json new file mode 100644 index 00000000000..b1493ad797d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fpcv-v65p-wv5w/GHSA-fpcv-v65p-wv5w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpcv-v65p-wv5w", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-29666" + ], + "details": "Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29666" + }, + { + "type": "WEB", + "url": "https://github.com/whgojp/cve-reports/wiki/There-is-a-weak-password-in-the-CMSV6-vehicle-monitoring-platform-system" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T19:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rx58-wmcf-8vpm/GHSA-rx58-wmcf-8vpm.json b/advisories/unreviewed/2024/03/GHSA-rx58-wmcf-8vpm/GHSA-rx58-wmcf-8vpm.json new file mode 100644 index 00000000000..06d6be3289b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rx58-wmcf-8vpm/GHSA-rx58-wmcf-8vpm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx58-wmcf-8vpm", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-2426" + ], + "details": "\nA denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will be required by the user to recover it.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2426" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/support/advisory.SD1664.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T21:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w4xx-6m5j-27fx/GHSA-w4xx-6m5j-27fx.json b/advisories/unreviewed/2024/03/GHSA-w4xx-6m5j-27fx/GHSA-w4xx-6m5j-27fx.json new file mode 100644 index 00000000000..588dab1f690 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w4xx-6m5j-27fx/GHSA-w4xx-6m5j-27fx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4xx-6m5j-27fx", + "modified": "2024-03-25T21:31:08Z", + "published": "2024-03-25T21:31:08Z", + "aliases": [ + "CVE-2024-29515" + ], + "details": "File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29515" + }, + { + "type": "WEB", + "url": "https://github.com/zzq66/cve7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-25T19:15:59Z" + } +} \ No newline at end of file