From 3b530f1f8f53e702a6845e277dd5a0bea2309518 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Sep 2024 12:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4vvg-656r-c25j.json | 6 +- .../GHSA-gm9h-7xvc-jg2f.json | 6 +- .../GHSA-j585-83xv-q5c7.json | 6 +- .../GHSA-xv3q-r363-84pg.json | 6 +- .../GHSA-j45q-g2vj-3f3r.json | 6 +- .../GHSA-jhfv-fgvm-hh32.json | 6 +- .../GHSA-mgxw-53vp-m2rh.json | 6 +- .../GHSA-86gv-6g4q-x856.json | 6 +- .../GHSA-395m-pvc6-8rvm.json | 2 +- .../GHSA-84mm-xgw8-mv4q.json | 2 +- .../GHSA-9qvw-gvq6-g569.json | 2 +- .../GHSA-f2hj-x395-x532.json | 2 +- .../GHSA-fmr5-j3hh-jpg4.json | 2 +- .../GHSA-g38w-3g42-rgpg.json | 6 +- .../GHSA-cc9x-2646-xv35.json | 6 +- .../GHSA-23q7-9vq5-jc43.json | 38 ++++++++++++ .../GHSA-36gf-ghcv-f3qq.json | 42 ++++++++++++++ .../GHSA-39wj-cf86-6v9w.json | 46 +++++++++++++++ .../GHSA-44w9-25wr-fjwf.json | 42 ++++++++++++++ .../GHSA-4p43-gfmp-qjmm.json | 42 ++++++++++++++ .../GHSA-5j8g-cmhw-g45p.json | 42 ++++++++++++++ .../GHSA-5v93-w7mf-hc4q.json | 42 ++++++++++++++ .../GHSA-6x28-mpjc-6r6h.json | 42 ++++++++++++++ .../GHSA-7mq7-p8xv-m9wf.json | 11 ++-- .../GHSA-84jf-469j-vw82.json | 42 ++++++++++++++ .../GHSA-88gp-qchm-x67w.json | 50 ++++++++++++++++ .../GHSA-8m3h-x229-2whw.json | 42 ++++++++++++++ .../GHSA-8vgr-3wf8-f94v.json | 42 ++++++++++++++ .../GHSA-8ww3-px7r-5vgq.json | 42 ++++++++++++++ .../GHSA-8xwp-62fq-vgg9.json | 42 ++++++++++++++ .../GHSA-cwq5-xwx7-85wm.json | 6 +- .../GHSA-g75j-c66m-v892.json | 42 ++++++++++++++ .../GHSA-gr6m-q82v-j96h.json | 42 ++++++++++++++ .../GHSA-h5rg-jpqm-g43g.json | 42 ++++++++++++++ .../GHSA-hxcg-5qf8-3h7f.json | 42 ++++++++++++++ .../GHSA-j2f4-8vj5-m862.json | 42 ++++++++++++++ .../GHSA-j3c4-46v5-v349.json | 42 ++++++++++++++ .../GHSA-p868-fp4q-w4hx.json | 42 ++++++++++++++ .../GHSA-p8g3-26x6-6m74.json | 43 ++++++++++++++ .../GHSA-pmp4-prv5-pw73.json | 42 ++++++++++++++ .../GHSA-qrv3-47g7-g24f.json | 42 ++++++++++++++ .../GHSA-qw7j-3hwv-9j97.json | 42 ++++++++++++++ .../GHSA-qw7v-5rg2-wrwr.json | 42 ++++++++++++++ .../GHSA-r2r6-q5j9-w7jx.json | 46 +++++++++++++++ .../GHSA-r9w3-4w3v-h5x6.json | 58 +++++++++++++++++++ .../GHSA-vp7w-7655-3xph.json | 42 ++++++++++++++ .../GHSA-wh3c-3qmr-4ghp.json | 42 ++++++++++++++ 47 files changed, 1356 insertions(+), 20 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json create mode 100644 advisories/unreviewed/2024/09/GHSA-36gf-ghcv-f3qq/GHSA-36gf-ghcv-f3qq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5j8g-cmhw-g45p/GHSA-5j8g-cmhw-g45p.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-84jf-469j-vw82/GHSA-84jf-469j-vw82.json create mode 100644 advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8m3h-x229-2whw/GHSA-8m3h-x229-2whw.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8vgr-3wf8-f94v/GHSA-8vgr-3wf8-f94v.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json create mode 100644 advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json create mode 100644 advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json create mode 100644 advisories/unreviewed/2024/09/GHSA-h5rg-jpqm-g43g/GHSA-h5rg-jpqm-g43g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hxcg-5qf8-3h7f/GHSA-hxcg-5qf8-3h7f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json create mode 100644 advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pmp4-prv5-pw73/GHSA-pmp4-prv5-pw73.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qrv3-47g7-g24f/GHSA-qrv3-47g7-g24f.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json create mode 100644 advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r9w3-4w3v-h5x6/GHSA-r9w3-4w3v-h5x6.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json diff --git a/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json b/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json index 6af07518249..3abdfde01f2 100644 --- a/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json +++ b/advisories/unreviewed/2022/05/GHSA-4vvg-656r-c25j/GHSA-4vvg-656r-c25j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vvg-656r-c25j", - "modified": "2024-07-09T12:30:54Z", + "modified": "2024-09-10T12:30:32Z", "published": "2022-05-13T01:02:38Z", "aliases": [ "CVE-2017-2680" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json b/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json index 1ddf7bbb0d6..a923ce4b513 100644 --- a/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json +++ b/advisories/unreviewed/2022/05/GHSA-gm9h-7xvc-jg2f/GHSA-gm9h-7xvc-jg2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gm9h-7xvc-jg2f", - "modified": "2023-01-10T12:30:27Z", + "modified": "2024-09-10T12:30:33Z", "published": "2022-05-24T16:58:25Z", "aliases": [ "CVE-2019-10923" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10923" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-349422.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-349422.pdf" diff --git a/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json b/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json index 2cb1d7b8031..6363ef0177d 100644 --- a/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json +++ b/advisories/unreviewed/2022/05/GHSA-j585-83xv-q5c7/GHSA-j585-83xv-q5c7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j585-83xv-q5c7", - "modified": "2024-07-09T12:30:54Z", + "modified": "2024-09-10T12:30:32Z", "published": "2022-05-13T01:02:35Z", "aliases": [ "CVE-2017-2681" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json b/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json index 2c348c5f143..7bfb54d7dc5 100644 --- a/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json +++ b/advisories/unreviewed/2022/05/GHSA-xv3q-r363-84pg/GHSA-xv3q-r363-84pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xv3q-r363-84pg", - "modified": "2023-12-12T12:30:41Z", + "modified": "2024-09-10T12:30:33Z", "published": "2022-05-24T17:44:31Z", "aliases": [ "CVE-2020-25236" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-25236" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-783481.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-783481.pdf" diff --git a/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json b/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json index 86c92d55e59..b7bf6f78cfc 100644 --- a/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json +++ b/advisories/unreviewed/2022/10/GHSA-j45q-g2vj-3f3r/GHSA-j45q-g2vj-3f3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j45q-g2vj-3f3r", - "modified": "2022-10-12T19:00:40Z", + "modified": "2024-09-10T12:30:33Z", "published": "2022-10-11T12:00:45Z", "aliases": [ "CVE-2022-36363" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36363" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf" diff --git a/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json b/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json index 8fdcf9a9c8c..4bf5fe7a5a8 100644 --- a/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json +++ b/advisories/unreviewed/2022/10/GHSA-jhfv-fgvm-hh32/GHSA-jhfv-fgvm-hh32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhfv-fgvm-hh32", - "modified": "2022-10-12T19:00:40Z", + "modified": "2024-09-10T12:30:33Z", "published": "2022-10-11T12:00:45Z", "aliases": [ "CVE-2022-36361" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36361" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf" diff --git a/advisories/unreviewed/2022/10/GHSA-mgxw-53vp-m2rh/GHSA-mgxw-53vp-m2rh.json b/advisories/unreviewed/2022/10/GHSA-mgxw-53vp-m2rh/GHSA-mgxw-53vp-m2rh.json index e661c9981c7..ab350ba1d61 100644 --- a/advisories/unreviewed/2022/10/GHSA-mgxw-53vp-m2rh/GHSA-mgxw-53vp-m2rh.json +++ b/advisories/unreviewed/2022/10/GHSA-mgxw-53vp-m2rh/GHSA-mgxw-53vp-m2rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgxw-53vp-m2rh", - "modified": "2022-10-12T19:00:40Z", + "modified": "2024-09-10T12:30:33Z", "published": "2022-10-11T12:00:45Z", "aliases": [ "CVE-2022-36362" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36362" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-955858.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-955858.pdf" diff --git a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json index b8d9143ce2a..4ee75523dee 100644 --- a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json +++ b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86gv-6g4q-x856", - "modified": "2024-08-13T09:30:52Z", + "modified": "2024-09-10T12:30:34Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44373" @@ -41,6 +41,10 @@ "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-699386.html" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-721642.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf" diff --git a/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json b/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json index 4a0a62dcd85..f8a6d018472 100644 --- a/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json +++ b/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-395m-pvc6-8rvm", - "modified": "2024-08-13T09:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46283" diff --git a/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json b/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json index 4fda6db5127..b15064cf80e 100644 --- a/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json +++ b/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84mm-xgw8-mv4q", - "modified": "2024-08-13T09:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46285" diff --git a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json index d2dcae6b2a5..8fc4d74da92 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json +++ b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvw-gvq6-g569", - "modified": "2024-08-13T09:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:53Z", "aliases": [ "CVE-2023-46281" diff --git a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json index 22073b9cc2c..82e8265b6f2 100644 --- a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json +++ b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2hj-x395-x532", - "modified": "2024-08-13T09:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46284" diff --git a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json index f8815e052cc..41fd243366f 100644 --- a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json +++ b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmr5-j3hh-jpg4", - "modified": "2024-08-13T09:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46282" diff --git a/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json b/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json index 08f4202369a..cd2ff4ca1f9 100644 --- a/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json +++ b/advisories/unreviewed/2023/12/GHSA-g38w-3g42-rgpg/GHSA-g38w-3g42-rgpg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g38w-3g42-rgpg", - "modified": "2023-12-12T12:30:51Z", + "modified": "2024-09-10T12:30:35Z", "published": "2023-12-12T12:30:51Z", "aliases": [ "CVE-2022-42784" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42784" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-844582.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-844582.pdf" diff --git a/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json b/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json index 9577b346c07..81544b6ca17 100644 --- a/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json +++ b/advisories/unreviewed/2024/03/GHSA-cc9x-2646-xv35/GHSA-cc9x-2646-xv35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc9x-2646-xv35", - "modified": "2024-03-12T12:30:48Z", + "modified": "2024-09-10T12:30:35Z", "published": "2024-03-12T12:30:48Z", "aliases": [ "CVE-2024-21483" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json new file mode 100644 index 00000000000..c01f4a42dec --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-23q7-9vq5-jc43/GHSA-23q7-9vq5-jc43.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23q7-9vq5-jc43", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-40754" + ], + "details": "Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40754" + }, + { + "type": "WEB", + "url": "https://github.com/Samsung/escargot/pull/1369" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-36gf-ghcv-f3qq/GHSA-36gf-ghcv-f3qq.json b/advisories/unreviewed/2024/09/GHSA-36gf-ghcv-f3qq/GHSA-36gf-ghcv-f3qq.json new file mode 100644 index 00000000000..a545be41bd8 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-36gf-ghcv-f3qq/GHSA-36gf-ghcv-f3qq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36gf-ghcv-f3qq", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2023-49069" + ], + "details": "A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.14.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.2 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.6 (All versions < V10.6.12 only if the basic authentication mechanism is used by the application), Mendix Runtime V8 (All versions only if the basic authentication mechanism is used by the application), Mendix Runtime V9 (All versions < V9.24.26 only if the basic authentication mechanism is used by the application). The authentication mechanism of affected applications contains an observable response discrepancy vulnerability when validating usernames. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49069" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-097435.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json b/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json new file mode 100644 index 00000000000..77af4f4da1a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-39wj-cf86-6v9w/GHSA-39wj-cf86-6v9w.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39wj-cf86-6v9w", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2023-2919" + ], + "details": "The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for unauthenticated attackers to enable or disable addons via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2919" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Ajax.php?rev=3128650#L506" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3148621/tutor/tags/2.7.5/classes/Ajax.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/992abd72-2a8e-4bda-94c2-4a7f88487906?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json b/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json new file mode 100644 index 00000000000..a798c19e18c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-44w9-25wr-fjwf/GHSA-44w9-25wr-fjwf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44w9-25wr-fjwf", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2023-30755" + ], + "details": "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-7 LTE (All versions < V3.5.20), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.5.20), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMATIC WinCC Runtime Advanced (All versions), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of the affected devices do not properly handle the shutdown or reboot request, which could lead to the clean up of certain resources. \n\nThis could allow a remote attacker with elevated privileges to cause a denial of service condition in the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30755" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-423808.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json b/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json new file mode 100644 index 00000000000..ba20cf5af8b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4p43-gfmp-qjmm/GHSA-4p43-gfmp-qjmm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p43-gfmp-qjmm", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2023-30756" + ], + "details": "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-7 LTE (All versions < V3.5.20), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.5.20), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMATIC WinCC Runtime Advanced (All versions), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of the affected devices do not properly handle certain errors when using the Expect HTTP request header, resulting in NULL dereference.\n\nThis could allow a remote attacker with no privileges to cause a denial of service condition in the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30756" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-423808.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5j8g-cmhw-g45p/GHSA-5j8g-cmhw-g45p.json b/advisories/unreviewed/2024/09/GHSA-5j8g-cmhw-g45p/GHSA-5j8g-cmhw-g45p.json new file mode 100644 index 00000000000..8e21281d87f --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5j8g-cmhw-g45p/GHSA-5j8g-cmhw-g45p.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j8g-cmhw-g45p", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-33698" + ], + "details": "A vulnerability has been identified in SIMATIC Information Server 2022 (All versions), SIMATIC Information Server 2024 (All versions), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33698" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-039007.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json b/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json new file mode 100644 index 00000000000..8c2d2749561 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5v93-w7mf-hc4q/GHSA-5v93-w7mf-hc4q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v93-w7mf-hc4q", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-32006" + ], + "details": "A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout. This could allow an attacker to bypass Multi-Factor Authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32006" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-417159.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json b/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json new file mode 100644 index 00000000000..ddd0a38a114 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6x28-mpjc-6r6h/GHSA-6x28-mpjc-6r6h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x28-mpjc-6r6h", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-43647" + ], + "details": "A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR30 (6ES7288-1SR30-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR40 (6ES7288-1SR40-0AA1) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR60 (6ES7288-1SR60-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST20 (6ES7288-1ST20-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST30 (6ES7288-1ST30-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST40 (6ES7288-1ST40-0AA1) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA0) (All versions), SIMATIC S7-200 SMART CPU ST60 (6ES7288-1ST60-0AA1) (All versions). Affected devices do not properly handle TCP packets with an incorrect structure. This could allow an unauthenticated remote attacker to cause a denial of service condition. To restore normal operations, the network cable of the device needs to be unplugged and re-plugged.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43647" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-969738.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json index b5e69ec0b15..65b26634c88 100644 --- a/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json +++ b/advisories/unreviewed/2024/09/GHSA-7mq7-p8xv-m9wf/GHSA-7mq7-p8xv-m9wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7mq7-p8xv-m9wf", - "modified": "2024-09-09T06:30:45Z", + "modified": "2024-09-10T12:30:35Z", "published": "2024-09-09T06:30:45Z", "aliases": [ "CVE-2024-45625" ], "details": "Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who follows a crafted URL and accesses the webpage with the web form created by Forminator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-09T05:15:01Z" diff --git a/advisories/unreviewed/2024/09/GHSA-84jf-469j-vw82/GHSA-84jf-469j-vw82.json b/advisories/unreviewed/2024/09/GHSA-84jf-469j-vw82/GHSA-84jf-469j-vw82.json new file mode 100644 index 00000000000..e4ffd79fd4b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-84jf-469j-vw82/GHSA-84jf-469j-vw82.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84jf-469j-vw82", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37993" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected applications do not authenticated the creation of Ajax2App instances. This could allow an unauthenticated attacker to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37993" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json b/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json new file mode 100644 index 00000000000..d0ef101fa10 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-88gp-qchm-x67w/GHSA-88gp-qchm-x67w.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88gp-qchm-x67w", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-8241" + ], + "details": "The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8241" + }, + { + "type": "WEB", + "url": "https://github.com/pixelgrade/nova-blocks/commit/655b5b804306c3ca3a59707cc2f12098e193b4ca" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3148752" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/nova-blocks/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3011befd-c0c6-4800-a370-e592c3ec483f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8m3h-x229-2whw/GHSA-8m3h-x229-2whw.json b/advisories/unreviewed/2024/09/GHSA-8m3h-x229-2whw/GHSA-8m3h-x229-2whw.json new file mode 100644 index 00000000000..4c5bc10a938 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8m3h-x229-2whw/GHSA-8m3h-x229-2whw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m3h-x229-2whw", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37995" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected application improperly handles error while a faulty certificate upload leading to crashing of application. This vulnerability could allow an attacker to disclose sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37995" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8vgr-3wf8-f94v/GHSA-8vgr-3wf8-f94v.json b/advisories/unreviewed/2024/09/GHSA-8vgr-3wf8-f94v/GHSA-8vgr-3wf8-f94v.json new file mode 100644 index 00000000000..17faf5aa16c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8vgr-3wf8-f94v/GHSA-8vgr-3wf8-f94v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vgr-3wf8-f94v", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-8369" + ], + "details": "The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or password-protected events.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8369" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/eventprime-event-calendar-management" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/97174ec0-a2b7-455e-9bf8-b6f51546beee?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json b/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json new file mode 100644 index 00000000000..725e0c8fdfd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8ww3-px7r-5vgq/GHSA-8ww3-px7r-5vgq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ww3-px7r-5vgq", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-42345" + ], + "details": "A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42345" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-869574.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json b/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json new file mode 100644 index 00000000000..438a174d950 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8xwp-62fq-vgg9/GHSA-8xwp-62fq-vgg9.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xwp-62fq-vgg9", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37991" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The service log files of the affected application can be accessed without proper authentication. This could allow an unauthenticated attacker to get access to sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37991" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json b/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json index f0346f96cc9..035d703b51b 100644 --- a/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json +++ b/advisories/unreviewed/2024/09/GHSA-cwq5-xwx7-85wm/GHSA-cwq5-xwx7-85wm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cwq5-xwx7-85wm", - "modified": "2024-09-06T06:31:41Z", + "modified": "2024-09-10T12:30:35Z", "published": "2024-09-06T06:31:41Z", "aliases": [ "CVE-2024-45751" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://github.com/fujita/tgt/compare/v1.0.92...v1.0.93" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2024/09/07/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json b/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json new file mode 100644 index 00000000000..cd116154dfc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g75j-c66m-v892/GHSA-g75j-c66m-v892.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g75j-c66m-v892", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-43781" + ], + "details": "A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection with using Create MyConfig (CMC) <= V4.8 SP1 HF6), SINUMERIK ONE (All versions < V6.23 in connection with using Create MyConfig (CMC) <= V6.6), SINUMERIK ONE (All versions < V6.15 SP4 in connection with using Create MyConfig (CMC) <= V6.6). Affected systems, that have been provisioned with Create MyConfig (CMC), contain a Insertion of Sensitive Information into Log File vulnerability. This could allow a local authenticated user with low privileges to read sensitive information and thus circumvent access restrictions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43781" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-097786.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json b/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json new file mode 100644 index 00000000000..a275671af5b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-gr6m-q82v-j96h/GHSA-gr6m-q82v-j96h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr6m-q82v-j96h", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-8645" + ], + "details": "SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8645" + }, + { + "type": "WEB", + "url": "https://gitlab.com/wireshark/wireshark/-/issues/19559" + }, + { + "type": "WEB", + "url": "https://www.wireshark.org/security/wnpa-sec-2024-10.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-824" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h5rg-jpqm-g43g/GHSA-h5rg-jpqm-g43g.json b/advisories/unreviewed/2024/09/GHSA-h5rg-jpqm-g43g/GHSA-h5rg-jpqm-g43g.json new file mode 100644 index 00000000000..113ed219d1b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-h5rg-jpqm-g43g/GHSA-h5rg-jpqm-g43g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5rg-jpqm-g43g", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-35783" + ], + "details": "A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions), SIMATIC Information Server 2022 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Process Historian 2020 (All versions), SIMATIC Process Historian 2022 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 18), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products run their DB server with elevated privileges which could allow an authenticated attacker to execute arbitrary OS commands with administrative privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35783" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-629254.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hxcg-5qf8-3h7f/GHSA-hxcg-5qf8-3h7f.json b/advisories/unreviewed/2024/09/GHSA-hxcg-5qf8-3h7f/GHSA-hxcg-5qf8-3h7f.json new file mode 100644 index 00000000000..0ea22b42329 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hxcg-5qf8-3h7f/GHSA-hxcg-5qf8-3h7f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxcg-5qf8-3h7f", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37992" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected devices does not properly handle the error in case of exceeding characters while setting SNMP leading to the restart of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37992" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json b/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json new file mode 100644 index 00000000000..9965f023723 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j2f4-8vj5-m862/GHSA-j2f4-8vj5-m862.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2f4-8vj5-m862", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-44087" + ], + "details": "A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp. This could allow an unauthenticated remote attacker to cause an integer overflow and crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44087" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-103653.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json b/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json new file mode 100644 index 00000000000..24f10a5c25a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-j3c4-46v5-v349/GHSA-j3c4-46v5-v349.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3c4-46v5-v349", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-45032" + ], + "details": "A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to impersonate other devices onboarded to the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45032" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-359713.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json b/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json new file mode 100644 index 00000000000..abf90e3351a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p868-fp4q-w4hx/GHSA-p868-fp4q-w4hx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p868-fp4q-w4hx", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-42344" + ], + "details": "A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to compromise the confidentiality of other users' configuration data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42344" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-417159.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json b/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json new file mode 100644 index 00000000000..db10372710c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-p8g3-26x6-6m74/GHSA-p8g3-26x6-6m74.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8g3-26x6-6m74", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-45845" + ], + "details": "nix 2.24 through 2.24.5 allows directory traversal via a symlink in a nar file, because of mishandling of a directory containing a symlink and a directory of the same name, aka GHSA-h4vv-h3jq-v493.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45845" + }, + { + "type": "WEB", + "url": "https://github.com/NixOS/nix/tags" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=41492994" + }, + { + "type": "WEB", + "url": "https://puckipedia.com/7hkj-98sq/qixt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pmp4-prv5-pw73/GHSA-pmp4-prv5-pw73.json b/advisories/unreviewed/2024/09/GHSA-pmp4-prv5-pw73/GHSA-pmp4-prv5-pw73.json new file mode 100644 index 00000000000..d204ed6fcda --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pmp4-prv5-pw73/GHSA-pmp4-prv5-pw73.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmp4-prv5-pw73", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-8543" + ], + "details": "The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [sciba] shortcode in all versions up to, and including, 0.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8543" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/slider-comparison-image-before-and-after/trunk/sciba.php#L39" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/14ab5d7c-ab46-4a53-b0d2-8b331e204cf3?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qrv3-47g7-g24f/GHSA-qrv3-47g7-g24f.json b/advisories/unreviewed/2024/09/GHSA-qrv3-47g7-g24f/GHSA-qrv3-47g7-g24f.json new file mode 100644 index 00000000000..b08c3270a6c --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qrv3-47g7-g24f/GHSA-qrv3-47g7-g24f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrv3-47g7-g24f", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37994" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected application contains a hidden configuration item to enable debug functionality. This could allow an attacker to gain insight into the internal configuration of the deployment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37994" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json b/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json new file mode 100644 index 00000000000..72d28bf87cc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qw7j-3hwv-9j97/GHSA-qw7j-3hwv-9j97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw7j-3hwv-9j97", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2024-37990" + ], + "details": "A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT (6GT2811-6CC10-2AA0) (All versions < V4.2), SIMATIC Reader RF615R ETSI (6GT2811-6CC10-0AA0) (All versions < V4.2), SIMATIC Reader RF615R FCC (6GT2811-6CC10-1AA0) (All versions < V4.2), SIMATIC Reader RF650R ARIB (6GT2811-6AB20-4AA0) (All versions < V4.2), SIMATIC Reader RF650R CMIIT (6GT2811-6AB20-2AA0) (All versions < V4.2), SIMATIC Reader RF650R ETSI (6GT2811-6AB20-0AA0) (All versions < V4.2), SIMATIC Reader RF650R FCC (6GT2811-6AB20-1AA0) (All versions < V4.2), SIMATIC Reader RF680R ARIB (6GT2811-6AA10-4AA0) (All versions < V4.2), SIMATIC Reader RF680R CMIIT (6GT2811-6AA10-2AA0) (All versions < V4.2), SIMATIC Reader RF680R ETSI (6GT2811-6AA10-0AA0) (All versions < V4.2), SIMATIC Reader RF680R FCC (6GT2811-6AA10-1AA0) (All versions < V4.2), SIMATIC Reader RF685R ARIB (6GT2811-6CA10-4AA0) (All versions < V4.2), SIMATIC Reader RF685R CMIIT (6GT2811-6CA10-2AA0) (All versions < V4.2), SIMATIC Reader RF685R ETSI (6GT2811-6CA10-0AA0) (All versions < V4.2), SIMATIC Reader RF685R FCC (6GT2811-6CA10-1AA0) (All versions < V4.2), SIMATIC RF1140R (6GT2831-6CB00) (All versions < V1.1), SIMATIC RF1170R (6GT2831-6BB00) (All versions < V1.1), SIMATIC RF166C (6GT2002-0EE20) (All versions < V2.2), SIMATIC RF185C (6GT2002-0JE10) (All versions < V2.2), SIMATIC RF186C (6GT2002-0JE20) (All versions < V2.2), SIMATIC RF186CI (6GT2002-0JE50) (All versions < V2.2), SIMATIC RF188C (6GT2002-0JE40) (All versions < V2.2), SIMATIC RF188CI (6GT2002-0JE60) (All versions < V2.2), SIMATIC RF360R (6GT2801-5BA30) (All versions < V2.2). The affected applications contain configuration files which can be modified. An attacker with privilege access can modify these files and enable features that are not released for this device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37990" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-765405.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json b/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json new file mode 100644 index 00000000000..56a1c5ac2f1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qw7v-5rg2-wrwr/GHSA-qw7v-5rg2-wrwr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw7v-5rg2-wrwr", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-41170" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications contain a stack based overflow vulnerability while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41170" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-427715.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json b/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json new file mode 100644 index 00000000000..3c55c97a14e --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r2r6-q5j9-w7jx/GHSA-r2r6-q5j9-w7jx.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2r6-q5j9-w7jx", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-6282" + ], + "details": "The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element in all versions up to, and including 2.0.6.4 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on the injected link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6282" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/master-addons/tags/2.0.6.2/assets/js/master-addons-scripts.js#L3398" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3146230" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8bab0acc-5a5d-4dd4-9201-199b7f5aaa69?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r9w3-4w3v-h5x6/GHSA-r9w3-4w3v-h5x6.json b/advisories/unreviewed/2024/09/GHSA-r9w3-4w3v-h5x6/GHSA-r9w3-4w3v-h5x6.json new file mode 100644 index 00000000000..12a48cdfe07 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r9w3-4w3v-h5x6/GHSA-r9w3-4w3v-h5x6.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9w3-4w3v-h5x6", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-7770" + ], + "details": "The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 6.5.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted upload permissions by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7770" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-manager/trunk/backend/app/Http/Controllers/FileManagerController.php#L26" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-manager/trunk/libs/elFinder/php/elFinder.class.php#L1210" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-manager/trunk/libs/elFinder/php/elFinder.class.php#L3257" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-manager/trunk/libs/elFinder/php/elFinderConnector.class.php#L160" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3138710" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9cae7702-e531-45b9-9131-42edbc073a07?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json b/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json new file mode 100644 index 00000000000..ecc30807e53 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vp7w-7655-3xph/GHSA-vp7w-7655-3xph.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp7w-7655-3xph", + "modified": "2024-09-10T12:30:38Z", + "published": "2024-09-10T12:30:38Z", + "aliases": [ + "CVE-2024-41171" + ], + "details": "A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access restrictions to scripts that are regularly executed by the system with elevated privileges. This could allow an authenticated local attacker to escalate their privileges in the underlying system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41171" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-342438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json b/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json new file mode 100644 index 00000000000..efb739a9081 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wh3c-3qmr-4ghp/GHSA-wh3c-3qmr-4ghp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh3c-3qmr-4ghp", + "modified": "2024-09-10T12:30:37Z", + "published": "2024-09-10T12:30:37Z", + "aliases": [ + "CVE-2023-28827" + ], + "details": "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-7 LTE (All versions < V3.5.20), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.5.20), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMATIC WinCC Runtime Advanced (All versions), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of the affected devices do not properly handle certain requests, causing a timeout in the watchdog, which could lead to the clean up of pointers. \n\nThis could allow a remote attacker to cause a denial of service condition in the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28827" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-423808.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T10:15:05Z" + } +} \ No newline at end of file