From 42b3b48d881bccc7d05636a8a2690b8b520ac8e2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Jan 2025 15:33:37 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-vx2v-7cpp-943m.json | 4 +- .../GHSA-2352-52mf-hwj3.json | 3 +- .../GHSA-3659-jjmv-v338.json | 15 +++++-- .../GHSA-77r5-rg8x-qv78.json | 11 +++-- .../GHSA-78xq-q56p-fpwx.json | 11 +++-- .../GHSA-92q5-jqvg-mhwp.json | 11 +++-- .../GHSA-h6m9-gq43-hhq2.json | 15 +++++-- .../GHSA-phvq-9637-vp75.json | 15 +++++-- .../GHSA-qp35-683c-hfxv.json | 11 +++-- .../GHSA-ccpq-qrrm-9f6q.json | 11 +++-- .../GHSA-62rm-mh7j-gv7j.json | 11 +++-- .../GHSA-xp2j-75cr-2mjj.json | 4 +- .../GHSA-8c3c-gvf8-p7v2.json | 6 ++- .../GHSA-2722-p93p-vrgm.json | 6 ++- .../GHSA-2hc6-xq49-vhg3.json | 40 +++++++++++++++++++ .../GHSA-373j-x448-854g.json | 11 +++-- .../GHSA-3wph-r629-c94g.json | 6 ++- .../GHSA-4pqh-gmhf-2qvf.json | 6 ++- .../GHSA-6wxc-jqg3-v947.json | 6 ++- .../GHSA-7g8h-978r-mhh2.json | 11 +++-- .../GHSA-7w6r-748w-mh52.json | 4 +- .../GHSA-85j8-g7vp-vxr9.json | 15 +++++-- .../GHSA-8hqm-m28g-xwhx.json | 40 +++++++++++++++++++ .../GHSA-938g-xvcv-qg4g.json | 6 ++- .../GHSA-cpr8-m35v-9vv2.json | 11 +++-- .../GHSA-f7vw-gj5c-49gc.json | 37 +++++++++++++++++ .../GHSA-f929-9mwj-xwvm.json | 11 +++-- .../GHSA-ff32-cmvq-x6c5.json | 11 +++-- .../GHSA-g42r-fh8w-cm5m.json | 6 ++- .../GHSA-mfc5-v837-8rxx.json | 40 +++++++++++++++++++ .../GHSA-mr76-pvc2-w479.json | 11 +++-- .../GHSA-p8gc-jwrx-pf65.json | 6 ++- .../GHSA-p9jv-279v-6p2j.json | 40 +++++++++++++++++++ .../GHSA-pp2w-p8jr-3p8j.json | 2 +- .../GHSA-qxc8-hg93-pqh7.json | 6 ++- .../GHSA-r3r4-jc6c-965m.json | 6 ++- .../GHSA-rwgq-wj29-fx3r.json | 11 +++-- .../GHSA-vj9p-8pwq-8v8j.json | 6 ++- .../GHSA-wpcm-3jpv-h3x5.json | 6 ++- .../GHSA-wpr4-69wr-rf9f.json | 36 +++++++++++++++++ 40 files changed, 453 insertions(+), 72 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2hc6-xq49-vhg3/GHSA-2hc6-xq49-vhg3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8hqm-m28g-xwhx/GHSA-8hqm-m28g-xwhx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f7vw-gj5c-49gc/GHSA-f7vw-gj5c-49gc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mfc5-v837-8rxx/GHSA-mfc5-v837-8rxx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p9jv-279v-6p2j/GHSA-p9jv-279v-6p2j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wpr4-69wr-rf9f/GHSA-wpr4-69wr-rf9f.json diff --git a/advisories/unreviewed/2023/06/GHSA-vx2v-7cpp-943m/GHSA-vx2v-7cpp-943m.json b/advisories/unreviewed/2023/06/GHSA-vx2v-7cpp-943m/GHSA-vx2v-7cpp-943m.json index bfe80b0e14c..b0199a29b46 100644 --- a/advisories/unreviewed/2023/06/GHSA-vx2v-7cpp-943m/GHSA-vx2v-7cpp-943m.json +++ b/advisories/unreviewed/2023/06/GHSA-vx2v-7cpp-943m/GHSA-vx2v-7cpp-943m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-2352-52mf-hwj3/GHSA-2352-52mf-hwj3.json b/advisories/unreviewed/2024/02/GHSA-2352-52mf-hwj3/GHSA-2352-52mf-hwj3.json index 0f3d78977c4..552a26e4ca2 100644 --- a/advisories/unreviewed/2024/02/GHSA-2352-52mf-hwj3/GHSA-2352-52mf-hwj3.json +++ b/advisories/unreviewed/2024/02/GHSA-2352-52mf-hwj3/GHSA-2352-52mf-hwj3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1394" + "CWE-1394", + "CWE-287" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-3659-jjmv-v338/GHSA-3659-jjmv-v338.json b/advisories/unreviewed/2024/02/GHSA-3659-jjmv-v338/GHSA-3659-jjmv-v338.json index 35eb2b1d4c3..7685ab601e0 100644 --- a/advisories/unreviewed/2024/02/GHSA-3659-jjmv-v338/GHSA-3659-jjmv-v338.json +++ b/advisories/unreviewed/2024/02/GHSA-3659-jjmv-v338/GHSA-3659-jjmv-v338.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3659-jjmv-v338", - "modified": "2024-02-29T12:31:06Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-29T12:31:06Z", "aliases": [ "CVE-2024-26607" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/bridge: sii902x: Fix probing race issue\n\nA null pointer dereference crash has been observed rarely on TI\nplatforms using sii9022 bridge:\n\n[ 53.271356] sii902x_get_edid+0x34/0x70 [sii902x]\n[ 53.276066] sii902x_bridge_get_edid+0x14/0x20 [sii902x]\n[ 53.281381] drm_bridge_get_edid+0x20/0x34 [drm]\n[ 53.286305] drm_bridge_connector_get_modes+0x8c/0xcc [drm_kms_helper]\n[ 53.292955] drm_helper_probe_single_connector_modes+0x190/0x538 [drm_kms_helper]\n[ 53.300510] drm_client_modeset_probe+0x1f0/0xbd4 [drm]\n[ 53.305958] __drm_fb_helper_initial_config_and_unlock+0x50/0x510 [drm_kms_helper]\n[ 53.313611] drm_fb_helper_initial_config+0x48/0x58 [drm_kms_helper]\n[ 53.320039] drm_fbdev_dma_client_hotplug+0x84/0xd4 [drm_dma_helper]\n[ 53.326401] drm_client_register+0x5c/0xa0 [drm]\n[ 53.331216] drm_fbdev_dma_setup+0xc8/0x13c [drm_dma_helper]\n[ 53.336881] tidss_probe+0x128/0x264 [tidss]\n[ 53.341174] platform_probe+0x68/0xc4\n[ 53.344841] really_probe+0x188/0x3c4\n[ 53.348501] __driver_probe_device+0x7c/0x16c\n[ 53.352854] driver_probe_device+0x3c/0x10c\n[ 53.357033] __device_attach_driver+0xbc/0x158\n[ 53.361472] bus_for_each_drv+0x88/0xe8\n[ 53.365303] __device_attach+0xa0/0x1b4\n[ 53.369135] device_initial_probe+0x14/0x20\n[ 53.373314] bus_probe_device+0xb0/0xb4\n[ 53.377145] deferred_probe_work_func+0xcc/0x124\n[ 53.381757] process_one_work+0x1f0/0x518\n[ 53.385770] worker_thread+0x1e8/0x3dc\n[ 53.389519] kthread+0x11c/0x120\n[ 53.392750] ret_from_fork+0x10/0x20\n\nThe issue here is as follows:\n\n- tidss probes, but is deferred as sii902x is still missing.\n- sii902x starts probing and enters sii902x_init().\n- sii902x calls drm_bridge_add(). Now the sii902x bridge is ready from\n DRM's perspective.\n- sii902x calls sii902x_audio_codec_init() and\n platform_device_register_data()\n- The registration of the audio platform device causes probing of the\n deferred devices.\n- tidss probes, which eventually causes sii902x_bridge_get_edid() to be\n called.\n- sii902x_bridge_get_edid() tries to use the i2c to read the edid.\n However, the sii902x driver has not set up the i2c part yet, leading\n to the crash.\n\nFix this by moving the drm_bridge_add() to the end of the\nsii902x_init(), which is also at the very end of sii902x_probe().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T12:15:47Z" diff --git a/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json b/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json index 6e1ec88d72b..cac063f0ad6 100644 --- a/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json +++ b/advisories/unreviewed/2024/02/GHSA-77r5-rg8x-qv78/GHSA-77r5-rg8x-qv78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-77r5-rg8x-qv78", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47029" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: connac: fix kernel warning adding monitor interface\n\nFix the following kernel warning adding a monitor interface in\nmt76_connac_mcu_uni_add_dev routine.\n\n[ 507.984882] ------------[ cut here ]------------\n[ 507.989515] WARNING: CPU: 1 PID: 3017 at mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.059379] CPU: 1 PID: 3017 Comm: ifconfig Not tainted 5.4.98 #0\n[ 508.065461] Hardware name: MT7622_MT7531 RFB (DT)\n[ 508.070156] pstate: 80000005 (Nzcv daif -PAN -UAO)\n[ 508.074939] pc : mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.081806] lr : mt7921_eeprom_init+0x1288/0x1cb8 [mt7921e]\n[ 508.087367] sp : ffffffc013a33930\n[ 508.090671] x29: ffffffc013a33930 x28: ffffff801e628ac0\n[ 508.095973] x27: ffffff801c7f1200 x26: ffffff801c7eb008\n[ 508.101275] x25: ffffff801c7eaef0 x24: ffffff801d025610\n[ 508.106577] x23: ffffff801d022990 x22: ffffff801d024de8\n[ 508.111879] x21: ffffff801d0226a0 x20: ffffff801c7eaee8\n[ 508.117181] x19: ffffff801d0226a0 x18: 000000005d00b000\n[ 508.122482] x17: 00000000ffffffff x16: 0000000000000000\n[ 508.127785] x15: 0000000000000080 x14: ffffff801d704000\n[ 508.133087] x13: 0000000000000040 x12: 0000000000000002\n[ 508.138389] x11: 000000000000000c x10: 0000000000000000\n[ 508.143691] x9 : 0000000000000020 x8 : 0000000000000001\n[ 508.148992] x7 : 0000000000000000 x6 : 0000000000000000\n[ 508.154294] x5 : ffffff801c7eaee8 x4 : 0000000000000006\n[ 508.159596] x3 : 0000000000000001 x2 : 0000000000000000\n[ 508.164898] x1 : ffffff801c7eac08 x0 : ffffff801d0226a0\n[ 508.170200] Call trace:\n[ 508.172640] mt76_connac_mcu_uni_add_dev+0x178/0x190 [mt76_connac_lib]\n[ 508.179159] mt7921_eeprom_init+0x1288/0x1cb8 [mt7921e]\n[ 508.184394] drv_add_interface+0x34/0x88 [mac80211]\n[ 508.189271] ieee80211_add_virtual_monitor+0xe0/0xb48 [mac80211]\n[ 508.195277] ieee80211_do_open+0x86c/0x918 [mac80211]\n[ 508.200328] ieee80211_do_open+0x900/0x918 [mac80211]\n[ 508.205372] __dev_open+0xcc/0x150\n[ 508.208763] __dev_change_flags+0x134/0x198\n[ 508.212937] dev_change_flags+0x20/0x60\n[ 508.216764] devinet_ioctl+0x3e8/0x748\n[ 508.220503] inet_ioctl+0x1e4/0x350\n[ 508.223983] sock_do_ioctl+0x48/0x2a0\n[ 508.227635] sock_ioctl+0x310/0x4f8\n[ 508.231116] do_vfs_ioctl+0xa4/0xac0\n[ 508.234681] ksys_ioctl+0x44/0x90\n[ 508.237985] __arm64_sys_ioctl+0x1c/0x48\n[ 508.241901] el0_svc_common.constprop.1+0x7c/0x100\n[ 508.246681] el0_svc_handler+0x18/0x20\n[ 508.250421] el0_svc+0x8/0x1c8\n[ 508.253465] ---[ end trace c7b90fee13d72c39 ]---\n[ 508.261278] ------------[ cut here ]------------", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-78xq-q56p-fpwx/GHSA-78xq-q56p-fpwx.json b/advisories/unreviewed/2024/02/GHSA-78xq-q56p-fpwx/GHSA-78xq-q56p-fpwx.json index 8a0ad2baedd..811e7598872 100644 --- a/advisories/unreviewed/2024/02/GHSA-78xq-q56p-fpwx/GHSA-78xq-q56p-fpwx.json +++ b/advisories/unreviewed/2024/02/GHSA-78xq-q56p-fpwx/GHSA-78xq-q56p-fpwx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78xq-q56p-fpwx", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46974" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix masking negation logic upon negative dst register\n\nThe negation logic for the case where the off_reg is sitting in the\ndst register is not correct given then we cannot just invert the add\nto a sub or vice versa. As a fix, perform the final bitwise and-op\nunconditionally into AX from the off_reg, then move the pointer from\nthe src to dst and finally use AX as the source for the original\npointer arithmetic operation such that the inversion yields a correct\nresult. The single non-AX mov in between is possible given constant\nblinding is retaining it as it's not an immediate based operation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json b/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json index e38b47f23ff..ceaf5a05479 100644 --- a/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json +++ b/advisories/unreviewed/2024/02/GHSA-92q5-jqvg-mhwp/GHSA-92q5-jqvg-mhwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92q5-jqvg-mhwp", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47043" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: core: Fix some resource leaks in the error path of 'venus_probe()'\n\nIf an error occurs after a successful 'of_icc_get()' call, it must be\nundone.\n\nUse 'devm_of_icc_get()' instead of 'of_icc_get()' to avoid the leak.\nUpdate the remove function accordingly and axe the now unneeded\n'icc_put()' calls.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:40Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json b/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json index 950771da575..af15cddcabb 100644 --- a/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json +++ b/advisories/unreviewed/2024/02/GHSA-h6m9-gq43-hhq2/GHSA-h6m9-gq43-hhq2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6m9-gq43-hhq2", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47026" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-clt: destroy sysfs after removing session from active list\n\nA session can be removed dynamically by sysfs interface \"remove_path\" that\neventually calls rtrs_clt_remove_path_from_sysfs function. The current\nrtrs_clt_remove_path_from_sysfs first removes the sysfs interfaces and\nfrees sess->stats object. Second it removes the session from the active\nlist.\n\nTherefore some functions could access non-connected session and access the\nfreed sess->stats object even-if they check the session status before\naccessing the session.\n\nFor instance rtrs_clt_request and get_next_path_min_inflight check the\nsession status and try to send IO to the session. The session status\ncould be changed when they are trying to send IO but they could not catch\nthe change and update the statistics information in sess->stats object,\nand generate use-after-free problem.\n(see: \"RDMA/rtrs-clt: Check state of the rtrs_clt_sess before reading its\nstats\")\n\nThis patch changes the rtrs_clt_remove_path_from_sysfs to remove the\nsession from the active session list and then destroy the sysfs\ninterfaces.\n\nEach function still should check the session status because closing or\nerror recovery paths can change the status.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json b/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json index ef82bb67b51..0e156a6df75 100644 --- a/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json +++ b/advisories/unreviewed/2024/02/GHSA-phvq-9637-vp75/GHSA-phvq-9637-vp75.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phvq-9637-vp75", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47040" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix overflows checks in provide buffers\n\nColin reported before possible overflow and sign extension problems in\nio_provide_buffers_prep(). As Linus pointed out previous attempt did nothing\nuseful, see d81269fecb8ce (\"io_uring: fix provide_buffers sign extension\").\n\nDo that with help of check__overflow helpers. And fix struct\nio_provide_buf::len type, as it doesn't make much sense to keep it\nsigned.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json b/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json index 4b523af0d0a..e09ece6bf7c 100644 --- a/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json +++ b/advisories/unreviewed/2024/02/GHSA-qp35-683c-hfxv/GHSA-qp35-683c-hfxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qp35-683c-hfxv", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Remove WO permissions on second-level paging entries\n\nWhen the first level page table is used for IOVA translation, it only\nsupports Read-Only and Read-Write permissions. The Write-Only permission\nis not supported as the PRESENT bit (implying Read permission) should\nalways set. When using second level, we still give separate permissions\nthat allows WriteOnly which seems inconsistent and awkward. We want to\nhave consistent behavior. After moving to 1st level, we don't want things\nto work sometimes, and break if we use 2nd level for the same mappings.\nHence remove this configuration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/03/GHSA-ccpq-qrrm-9f6q/GHSA-ccpq-qrrm-9f6q.json b/advisories/unreviewed/2024/03/GHSA-ccpq-qrrm-9f6q/GHSA-ccpq-qrrm-9f6q.json index a709f416257..fe8bc073b96 100644 --- a/advisories/unreviewed/2024/03/GHSA-ccpq-qrrm-9f6q/GHSA-ccpq-qrrm-9f6q.json +++ b/advisories/unreviewed/2024/03/GHSA-ccpq-qrrm-9f6q/GHSA-ccpq-qrrm-9f6q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ccpq-qrrm-9f6q", - "modified": "2024-03-02T00:31:30Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-03-02T00:31:30Z", "aliases": [ "CVE-2021-47073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios\n\ninit_dell_smbios_wmi() only registers the dell_smbios_wmi_driver on systems\nwhere the Dell WMI interface is supported. While exit_dell_smbios_wmi()\nunregisters it unconditionally, this leads to the following oops:\n\n[ 175.722921] ------------[ cut here ]------------\n[ 175.722925] Unexpected driver unregister!\n[ 175.722939] WARNING: CPU: 1 PID: 3630 at drivers/base/driver.c:194 driver_unregister+0x38/0x40\n...\n[ 175.723089] Call Trace:\n[ 175.723094] cleanup_module+0x5/0xedd [dell_smbios]\n...\n[ 175.723148] ---[ end trace 064c34e1ad49509d ]---\n\nMake the unregister happen on the same condition the register happens\nto fix this.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json b/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json index 5c852fcd675..bac90c8a6d0 100644 --- a/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json +++ b/advisories/unreviewed/2024/04/GHSA-62rm-mh7j-gv7j/GHSA-62rm-mh7j-gv7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-62rm-mh7j-gv7j", - "modified": "2024-04-11T06:30:35Z", + "modified": "2025-01-09T15:31:50Z", "published": "2024-04-11T06:30:35Z", "aliases": [ "CVE-2024-30916" ], "details": "An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-11T06:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json index 6eb703edecc..af9b95950d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json +++ b/advisories/unreviewed/2024/04/GHSA-xp2j-75cr-2mjj/GHSA-xp2j-75cr-2mjj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json index 7f507defb98..d9ce59f2419 100644 --- a/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json +++ b/advisories/unreviewed/2024/11/GHSA-8c3c-gvf8-p7v2/GHSA-8c3c-gvf8-p7v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8c3c-gvf8-p7v2", - "modified": "2024-12-18T09:31:35Z", + "modified": "2025-01-09T15:31:51Z", "published": "2024-11-26T18:38:52Z", "aliases": [ "CVE-2024-52337" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:11161" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0195" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-52337" diff --git a/advisories/unreviewed/2025/01/GHSA-2722-p93p-vrgm/GHSA-2722-p93p-vrgm.json b/advisories/unreviewed/2025/01/GHSA-2722-p93p-vrgm/GHSA-2722-p93p-vrgm.json index 4c714462b2f..b0da7c22a81 100644 --- a/advisories/unreviewed/2025/01/GHSA-2722-p93p-vrgm/GHSA-2722-p93p-vrgm.json +++ b/advisories/unreviewed/2025/01/GHSA-2722-p93p-vrgm/GHSA-2722-p93p-vrgm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2722-p93p-vrgm", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43657" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root\n\nThis issue affects Iocharger firmware for AC model chargers before version 24120701.\n\nLikelihood: High. However, the attacker will need a (low privilege) account to gain access to the action.exe CGI binary and upload the crafted firmware file, or convince a user with such access to upload it.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services.\n\nCVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and compromised devices can be used to pivot into networks that should potentially not be accessible (SC:L/SI:L/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-2hc6-xq49-vhg3/GHSA-2hc6-xq49-vhg3.json b/advisories/unreviewed/2025/01/GHSA-2hc6-xq49-vhg3/GHSA-2hc6-xq49-vhg3.json new file mode 100644 index 00000000000..99eb8b858e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2hc6-xq49-vhg3/GHSA-2hc6-xq49-vhg3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hc6-xq49-vhg3", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2023-24011" + ], + "details": "An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24011" + }, + { + "type": "WEB", + "url": "https://github.com/ros2/sros2/issues/282" + }, + { + "type": "WEB", + "url": "https://gist.github.com/vmayoral/235c02d0b0ef85a29812eff6980ff80d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-373j-x448-854g/GHSA-373j-x448-854g.json b/advisories/unreviewed/2025/01/GHSA-373j-x448-854g/GHSA-373j-x448-854g.json index 55d51f85242..39eaa93ffbe 100644 --- a/advisories/unreviewed/2025/01/GHSA-373j-x448-854g/GHSA-373j-x448-854g.json +++ b/advisories/unreviewed/2025/01/GHSA-373j-x448-854g/GHSA-373j-x448-854g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-373j-x448-854g", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-12805" ], "details": "A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-134" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T08:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3wph-r629-c94g/GHSA-3wph-r629-c94g.json b/advisories/unreviewed/2025/01/GHSA-3wph-r629-c94g/GHSA-3wph-r629-c94g.json index 3cceee10c42..8ba87d684ed 100644 --- a/advisories/unreviewed/2025/01/GHSA-3wph-r629-c94g/GHSA-3wph-r629-c94g.json +++ b/advisories/unreviewed/2025/01/GHSA-3wph-r629-c94g/GHSA-3wph-r629-c94g.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wph-r629-c94g", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43649" ], "details": "Authenticated command injection in the filename of a .exe request leads to remote code execution as the root user.\n\nThis issue affects Iocharger firmware for AC models before version 24120701.\n\nLikelihood: Moderate – This action is not a common place for command injection vulnerabilities to occur. Thus, an attacker will likely only be able to find this vulnerability by reverse-engineering the firmware or trying it on all fields. The attacker will also need a (low privilege) account to gain access to the binary, or convince a user with such access to execute a payload.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete files and services.\n\nCVSS clarification: This attack can be performed over any network conenction serving the web interfacr (AV:N), and there are not additional mitigating measures that need to be circumvented (AC:L) or other prerequisites (AT:N). The attack does require privileges, but the level does not matter (PR:L), there is no user interaction required (UI:N). The attack leeds to a full compromised of the charger (VC:H/VI:H/VA:H) and a compromised charger can be used to \"pivot\" to networks that should normally not be reachable (SC:L/SI:L/SA:H). Because this is an EV chargers with significant pwoer, there is a potential safety imp0act (S:P). THis attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-4pqh-gmhf-2qvf/GHSA-4pqh-gmhf-2qvf.json b/advisories/unreviewed/2025/01/GHSA-4pqh-gmhf-2qvf/GHSA-4pqh-gmhf-2qvf.json index f1a31290ab9..09125e1f424 100644 --- a/advisories/unreviewed/2025/01/GHSA-4pqh-gmhf-2qvf/GHSA-4pqh-gmhf-2qvf.json +++ b/advisories/unreviewed/2025/01/GHSA-4pqh-gmhf-2qvf/GHSA-4pqh-gmhf-2qvf.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4pqh-gmhf-2qvf", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43656" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root\n\nThis issue affects Iocharger firmware for AC model chargers before version 24120701.\n\nLikelihood: Moderate – It might be difficult for an attacker to identify the file structure of the directory, and then modify the backup to add a new CGI script in the correct directory. Furthermore, the attacker will need an account to restore the settings backup, or convince a user with such access to upload a modified backup file.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and deletefiles and services.\n\nCVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and compromised devices can be used to pivot into networks that should potentially not be accessible (SC:L/SI:L/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-6wxc-jqg3-v947/GHSA-6wxc-jqg3-v947.json b/advisories/unreviewed/2025/01/GHSA-6wxc-jqg3-v947/GHSA-6wxc-jqg3-v947.json index fefad157d01..9e06315ee4d 100644 --- a/advisories/unreviewed/2025/01/GHSA-6wxc-jqg3-v947/GHSA-6wxc-jqg3-v947.json +++ b/advisories/unreviewed/2025/01/GHSA-6wxc-jqg3-v947/GHSA-6wxc-jqg3-v947.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6wxc-jqg3-v947", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43661" ], "details": "The .so library, which is used by , is\nvulnerable to a buffer overflow in the code that handles the deletion\nof certificates. This buffer overflow can be triggered by providing a\nlong file path to the action of the .exe CGI binary or\nto the .sh CGI script. This binary or script will write this\nfile path to , which is then\nread by .so\n\n\nThis issue affects Iocharger firmware for AC models before version 24120701.\n\nLikelihood: Moderate – An attacker will have to find this exploit by\neither obtaining the binaries involved in this vulnerability, or by trial\nand error. Furthermore, the attacker will need a (low privilege)\naccount to gain access to the .exe CGI binary or .sh\nscript to trigger the vulnerability, or convince a user with such access\nsend an HTTP request that triggers it.\n\n\nImpact: High – The process, which we assume is\nresponsible for OCPP communication, will keep crashing after\nperforming the exploit. This happens because the buffer overflow\ncauses the process to segfault before\n is removed. This means that,\neven though is automatically restarted, it will crash\nagain as soon as it tries to parse the text file.\n\nCVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N), and there are no additional security measure sin place that need to be circumvented (AC:L), the attack does not rely on preconditions (AT:N). The attack does require authentication, but the level of authentication is irrelevant (PR:L), it does not require user interaction (UI:N). The attack leads to reducred availability of the device (VC:N/VI:N/VA:H). THere is not impact on subsequent systems. (SC:N/SI:N/SA:N). Alltough this device is an EV charger handing significant amounts of power, we do not forsee a safety impact. The attack can be automated (AU:Y). Because the DoS condition is written to disk persistantly, it cannot be recovered by the user (R:I).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:I/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-7g8h-978r-mhh2/GHSA-7g8h-978r-mhh2.json b/advisories/unreviewed/2025/01/GHSA-7g8h-978r-mhh2/GHSA-7g8h-978r-mhh2.json index 4118dff82a0..de84d750cb3 100644 --- a/advisories/unreviewed/2025/01/GHSA-7g8h-978r-mhh2/GHSA-7g8h-978r-mhh2.json +++ b/advisories/unreviewed/2025/01/GHSA-7g8h-978r-mhh2/GHSA-7g8h-978r-mhh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g8h-978r-mhh2", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-12803" ], "details": "A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash a firewall and potentially leads to code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-121" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T08:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7w6r-748w-mh52/GHSA-7w6r-748w-mh52.json b/advisories/unreviewed/2025/01/GHSA-7w6r-748w-mh52/GHSA-7w6r-748w-mh52.json index 2bb247406fa..2fcd7799447 100644 --- a/advisories/unreviewed/2025/01/GHSA-7w6r-748w-mh52/GHSA-7w6r-748w-mh52.json +++ b/advisories/unreviewed/2025/01/GHSA-7w6r-748w-mh52/GHSA-7w6r-748w-mh52.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json b/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json index 9a719bb7bbd..1d41634eeed 100644 --- a/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json +++ b/advisories/unreviewed/2025/01/GHSA-85j8-g7vp-vxr9/GHSA-85j8-g7vp-vxr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-85j8-g7vp-vxr9", - "modified": "2025-01-09T06:30:24Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T06:30:24Z", "aliases": [ "CVE-2024-12717" ], "details": "The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T06:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8hqm-m28g-xwhx/GHSA-8hqm-m28g-xwhx.json b/advisories/unreviewed/2025/01/GHSA-8hqm-m28g-xwhx/GHSA-8hqm-m28g-xwhx.json new file mode 100644 index 00000000000..08989801e07 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8hqm-m28g-xwhx/GHSA-8hqm-m28g-xwhx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hqm-m28g-xwhx", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2023-24010" + ], + "details": "An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24010" + }, + { + "type": "WEB", + "url": "https://github.com/ros2/sros2/issues/282" + }, + { + "type": "WEB", + "url": "https://gist.github.com/vmayoral/235c02d0b0ef85a29812eff6980ff80d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-938g-xvcv-qg4g/GHSA-938g-xvcv-qg4g.json b/advisories/unreviewed/2025/01/GHSA-938g-xvcv-qg4g/GHSA-938g-xvcv-qg4g.json index c5b85054f3a..081ab4eed79 100644 --- a/advisories/unreviewed/2025/01/GHSA-938g-xvcv-qg4g/GHSA-938g-xvcv-qg4g.json +++ b/advisories/unreviewed/2025/01/GHSA-938g-xvcv-qg4g/GHSA-938g-xvcv-qg4g.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-938g-xvcv-qg4g", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43654" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Command Injection as root\nThis issue affects all Iocharger AC EV charger models on a firmware version before 25010801.\n\nLikelihood: Moderate – The binary does not seem to be used by the web interface, so it might be more difficult to find. It seems to be largely the same binary as used by the Iocharger Pedestal charging station, however. The attacker will also need a (low privilege) account to gain access to the binary, or convince a user with such access to execute a crafted HTTP request.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete\nfiles and services.\n\nCVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and compromised devices can be used to pivot into networks that should potentially not be accessible (SC:L/SI:L/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-cpr8-m35v-9vv2/GHSA-cpr8-m35v-9vv2.json b/advisories/unreviewed/2025/01/GHSA-cpr8-m35v-9vv2/GHSA-cpr8-m35v-9vv2.json index 0fe47465d89..2c068903548 100644 --- a/advisories/unreviewed/2025/01/GHSA-cpr8-m35v-9vv2/GHSA-cpr8-m35v-9vv2.json +++ b/advisories/unreviewed/2025/01/GHSA-cpr8-m35v-9vv2/GHSA-cpr8-m35v-9vv2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cpr8-m35v-9vv2", - "modified": "2025-01-09T09:31:41Z", + "modified": "2025-01-09T15:31:50Z", "published": "2025-01-09T09:31:41Z", "aliases": [ "CVE-2024-40762" ], "details": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-338" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T07:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f7vw-gj5c-49gc/GHSA-f7vw-gj5c-49gc.json b/advisories/unreviewed/2025/01/GHSA-f7vw-gj5c-49gc/GHSA-f7vw-gj5c-49gc.json new file mode 100644 index 00000000000..5a4156797d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f7vw-gj5c-49gc/GHSA-f7vw-gj5c-49gc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7vw-gj5c-49gc", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2024-43176" + ], + "details": "IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43176" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7174640" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276", + "CWE-282" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T14:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f929-9mwj-xwvm/GHSA-f929-9mwj-xwvm.json b/advisories/unreviewed/2025/01/GHSA-f929-9mwj-xwvm/GHSA-f929-9mwj-xwvm.json index 79633ad2386..46fd9526e89 100644 --- a/advisories/unreviewed/2025/01/GHSA-f929-9mwj-xwvm/GHSA-f929-9mwj-xwvm.json +++ b/advisories/unreviewed/2025/01/GHSA-f929-9mwj-xwvm/GHSA-f929-9mwj-xwvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f929-9mwj-xwvm", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-40765" ], "details": "An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-190" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T08:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ff32-cmvq-x6c5/GHSA-ff32-cmvq-x6c5.json b/advisories/unreviewed/2025/01/GHSA-ff32-cmvq-x6c5/GHSA-ff32-cmvq-x6c5.json index 8bba6599c34..a930c0bc7f9 100644 --- a/advisories/unreviewed/2025/01/GHSA-ff32-cmvq-x6c5/GHSA-ff32-cmvq-x6c5.json +++ b/advisories/unreviewed/2025/01/GHSA-ff32-cmvq-x6c5/GHSA-ff32-cmvq-x6c5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ff32-cmvq-x6c5", - "modified": "2025-01-09T09:31:43Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:43Z", "aliases": [ "CVE-2024-12802" ], "details": "SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-305" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T09:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g42r-fh8w-cm5m/GHSA-g42r-fh8w-cm5m.json b/advisories/unreviewed/2025/01/GHSA-g42r-fh8w-cm5m/GHSA-g42r-fh8w-cm5m.json index 13b81bbf6f7..50cd6f3de2b 100644 --- a/advisories/unreviewed/2025/01/GHSA-g42r-fh8w-cm5m/GHSA-g42r-fh8w-cm5m.json +++ b/advisories/unreviewed/2025/01/GHSA-g42r-fh8w-cm5m/GHSA-g42r-fh8w-cm5m.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g42r-fh8w-cm5m", - "modified": "2025-01-09T09:31:43Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:43Z", "aliases": [ "CVE-2024-43663" ], "details": "There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affects Iocharger firmware for AC model chargers beforeversion 24120701.\n\nLikelihood: High – Given the prevalence of these buffer overflows, and the clear error message of the web server, an attacker is very likely to be able to find these vulnerabilities.\n\nImpact: Low – Usually, overflowing one of these buffers just causes a segmentation fault of the CGI binary, which causes the web server to return a 502 Bad Gateway error. However the webserver itself is not affected, and no DoS can be achieved. Abusing these buffer overflows in a meaningful way requires highly technical knowledge, especially since ASLR also seems to be enabled on the charging station. However, a skilled attacker might be able to use one of these buffer overflows to obtain remote code execution.\n\nCVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N), and there are no additional security measure sin place that need to be circumvented (AC:L), the attack does not rely on preconditions (AT:N). The attack does require authentication, but the level of authentication is irrelevant (PR:L), it does not require user interaction (UI:N). The attack has a small impact on the availability of the device (VC:N/VI:N/VA:L). There is no impact on subsequent systems. (SC:N/SI:N/SA:N). While this device is an EV charger handing significant amounts of power, we do not expect  this vulnerability to have a safety impact. The attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-mfc5-v837-8rxx/GHSA-mfc5-v837-8rxx.json b/advisories/unreviewed/2025/01/GHSA-mfc5-v837-8rxx/GHSA-mfc5-v837-8rxx.json new file mode 100644 index 00000000000..0039acdba9f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mfc5-v837-8rxx/GHSA-mfc5-v837-8rxx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfc5-v837-8rxx", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2023-24012" + ], + "details": "An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24012" + }, + { + "type": "WEB", + "url": "https://github.com/ros2/sros2/issues/282" + }, + { + "type": "WEB", + "url": "https://gist.github.com/vmayoral/235c02d0b0ef85a29812eff6980ff80d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mr76-pvc2-w479/GHSA-mr76-pvc2-w479.json b/advisories/unreviewed/2025/01/GHSA-mr76-pvc2-w479/GHSA-mr76-pvc2-w479.json index 451a67f024f..4bb53d28d22 100644 --- a/advisories/unreviewed/2025/01/GHSA-mr76-pvc2-w479/GHSA-mr76-pvc2-w479.json +++ b/advisories/unreviewed/2025/01/GHSA-mr76-pvc2-w479/GHSA-mr76-pvc2-w479.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mr76-pvc2-w479", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-53705" ], "details": "A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T07:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p8gc-jwrx-pf65/GHSA-p8gc-jwrx-pf65.json b/advisories/unreviewed/2025/01/GHSA-p8gc-jwrx-pf65/GHSA-p8gc-jwrx-pf65.json index a5046c8a996..5d63f42fadd 100644 --- a/advisories/unreviewed/2025/01/GHSA-p8gc-jwrx-pf65/GHSA-p8gc-jwrx-pf65.json +++ b/advisories/unreviewed/2025/01/GHSA-p8gc-jwrx-pf65/GHSA-p8gc-jwrx-pf65.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8gc-jwrx-pf65", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43653" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Injection as root\nThis issue affects Iocharger firmware for AC model chargers before version 24120701.\n\nLikelihood: Moderate – The binary does not seem to be used by the web interface, so it might be more difficult to find. It seems to be largely the same binary as used by the Iocharger Pedestal charging station, however. The attacker will also need a (low privilege) account to gain access to the binary, or convince a user with such access to execute a crafted HTTP request.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete\nfiles and services.\n\nCVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, but the level of authentication does not matter (PR:L), nor is any user interaction required (UI:N). The attack leads to a full compromised (VC:H/VI:H/VA:H), and compromised devices can be used to pivot into networks that should potentially not be accessible (SC:L/SI:L/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-p9jv-279v-6p2j/GHSA-p9jv-279v-6p2j.json b/advisories/unreviewed/2025/01/GHSA-p9jv-279v-6p2j/GHSA-p9jv-279v-6p2j.json new file mode 100644 index 00000000000..097ef93e2a1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p9jv-279v-6p2j/GHSA-p9jv-279v-6p2j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9jv-279v-6p2j", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2024-10106" + ], + "details": "A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's buffer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10106" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm00000I1JawIAF" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/simplicity_sdk/releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pp2w-p8jr-3p8j/GHSA-pp2w-p8jr-3p8j.json b/advisories/unreviewed/2025/01/GHSA-pp2w-p8jr-3p8j/GHSA-pp2w-p8jr-3p8j.json index 2b34891f78c..b0f3babaaa4 100644 --- a/advisories/unreviewed/2025/01/GHSA-pp2w-p8jr-3p8j/GHSA-pp2w-p8jr-3p8j.json +++ b/advisories/unreviewed/2025/01/GHSA-pp2w-p8jr-3p8j/GHSA-pp2w-p8jr-3p8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pp2w-p8jr-3p8j", - "modified": "2025-01-09T12:30:55Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T12:30:55Z", "aliases": [ "CVE-2024-12605" diff --git a/advisories/unreviewed/2025/01/GHSA-qxc8-hg93-pqh7/GHSA-qxc8-hg93-pqh7.json b/advisories/unreviewed/2025/01/GHSA-qxc8-hg93-pqh7/GHSA-qxc8-hg93-pqh7.json index 20403c860c7..710dd7eca44 100644 --- a/advisories/unreviewed/2025/01/GHSA-qxc8-hg93-pqh7/GHSA-qxc8-hg93-pqh7.json +++ b/advisories/unreviewed/2025/01/GHSA-qxc8-hg93-pqh7/GHSA-qxc8-hg93-pqh7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxc8-hg93-pqh7", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43659" ], "details": "After gaining access to the firmware of a charging station, a file at can be accessed to obtain default credentials that are the same across all Iocharger AC model EV chargers.\n\nThis issue affects Iocharger firmware for AC models before firmware version 25010801. \n\nThe issue is addressed by requiring a mandatory password change on first login, it is still recommended to change the password on older models.\n\nLikelihood: Moderate – The attacker will first have to abuse a code execution or file inclusion vulnerability (for example by using .sh) to gain access to the .json file, or obtain a firmware dump of the charging station or obtain the firmware via other channels.\n\nImpact: Critical – All chargers using Iocharger firmware for AC models started with the same initial password. For models with firmware version before 25010801 a password change was not mandatory. It is therefore very likely that this firmware password is still active on many chargers. These credentials could, once obtained, allow an attacker to log into many Iocharger charging station, and allow them to execute arbitrary commands via the System → Custom page.\n\nCVSS clarification: Any network interface serving the web ui is vulnerable (AV:N) and there are not additional security measures to circumvent (AC:L), nor does the attack require and existing preconditions (AT:N). The attack is authenticated, and requires high privileges (PR:H), there is no user interaction required (UI:N). The attack leads to a compromised of the confidentialy of the \"super user\" credentials of the device (VC:H/VI:N/VA:N), and can subsequently be used to full compromise and other devices (SC:H/SI:H/SA:H). Becuase this is an EV charger handing significant power, there is a potential safety impact (S:P). This attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-r3r4-jc6c-965m/GHSA-r3r4-jc6c-965m.json b/advisories/unreviewed/2025/01/GHSA-r3r4-jc6c-965m/GHSA-r3r4-jc6c-965m.json index 117e73636d6..357d50cc497 100644 --- a/advisories/unreviewed/2025/01/GHSA-r3r4-jc6c-965m/GHSA-r3r4-jc6c-965m.json +++ b/advisories/unreviewed/2025/01/GHSA-r3r4-jc6c-965m/GHSA-r3r4-jc6c-965m.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r3r4-jc6c-965m", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43648" ], "details": "Command injection in the parameter of a .exe request leads to remote code execution as the root user.\n\nThis issue affects Iocharger firmware for AC models before version 24120701.\n\nLikelihood: Moderate – This action is not a common place for command injection vulnerabilities to occur. Thus, an attacker will likely only be able to find this vulnerability by reverse-engineering the firmware or trying it on all fields. The attacker will also need a (low privilege) account to gain access to the binary, or convince a user with such access to execute a payload.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete files and services.\n\nCVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N), and there are no additional security measure sin place that need to be circumvented (AC:L), the attack does not rely on preconditions (AT:N). The attack does require authentication, but the level of authentication is irrelevant (PR:L), it does not require user interaction (UI:N). If is a full system compromise, potentially fully compromising confidentiality, integrity and availability of the devicer (VC:H/VI:H/VA:H).  A compromised charger can be used to \"pivot\" onto networks that should otherwise be closed, cause a low confidentiality and interity impact on subsequent systems. (SC:L/SI:L/SA:H). Because this device is an EV charger handing significant amounts of power, we suspect this vulnerability can have a safety impact (S:P). The attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-rwgq-wj29-fx3r/GHSA-rwgq-wj29-fx3r.json b/advisories/unreviewed/2025/01/GHSA-rwgq-wj29-fx3r/GHSA-rwgq-wj29-fx3r.json index 31f44c0d494..c5a091dfa04 100644 --- a/advisories/unreviewed/2025/01/GHSA-rwgq-wj29-fx3r/GHSA-rwgq-wj29-fx3r.json +++ b/advisories/unreviewed/2025/01/GHSA-rwgq-wj29-fx3r/GHSA-rwgq-wj29-fx3r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rwgq-wj29-fx3r", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:50Z", "published": "2025-01-09T09:31:41Z", "aliases": [ "CVE-2024-53704" ], "details": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T07:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vj9p-8pwq-8v8j/GHSA-vj9p-8pwq-8v8j.json b/advisories/unreviewed/2025/01/GHSA-vj9p-8pwq-8v8j/GHSA-vj9p-8pwq-8v8j.json index d021130fc73..e830426a29e 100644 --- a/advisories/unreviewed/2025/01/GHSA-vj9p-8pwq-8v8j/GHSA-vj9p-8pwq-8v8j.json +++ b/advisories/unreviewed/2025/01/GHSA-vj9p-8pwq-8v8j/GHSA-vj9p-8pwq-8v8j.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj9p-8pwq-8v8j", - "modified": "2025-01-09T09:31:43Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43660" ], "details": "The CGI script .sh can be used to download any file on the filesystem.\n\nThis issue affects Iocharger firmware for AC model chargers beforeversion 24120701.\n\nLikelihood: High, but credentials required.\n\nImpact: Critical – The script can be used to download any file on the filesystem, including sensitive files such as /etc/shadow, the CGI script source code or binaries and configuration files.\n\nCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/S:P/AU:Y\nCVSS clarification. The attack can be executed over any network connection the station is listening to and serves the web interface (AV:N), and there are no additional security measure sin place that need to be circumvented (AC:L), the attack does not rely on preconditions (AT:N). The attack does require authentication, but the level of authentication is irrelevant (PR:L), it does not require user interaction (UI:N). The confidentiality of all files of the devicd can be compromised (VC:H/VI:N/VA:N). There is no impact on subsequent systems. (SC:N/SI:N/SA:N). While this device is an EV charger handing significant amounts of power, this attack in isolation does not have a safety impact. The attack can be automated (AU:Y).", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-wpcm-3jpv-h3x5/GHSA-wpcm-3jpv-h3x5.json b/advisories/unreviewed/2025/01/GHSA-wpcm-3jpv-h3x5/GHSA-wpcm-3jpv-h3x5.json index 2cfa9b8093c..9ef5034e80c 100644 --- a/advisories/unreviewed/2025/01/GHSA-wpcm-3jpv-h3x5/GHSA-wpcm-3jpv-h3x5.json +++ b/advisories/unreviewed/2025/01/GHSA-wpcm-3jpv-h3x5/GHSA-wpcm-3jpv-h3x5.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpcm-3jpv-h3x5", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T15:31:51Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-43652" ], "details": "Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root\nThis issue affects Iocharger firmware for AC model chargers before version 24120701\n\nLikelihood: Moderate – The binary does not seem to be used by the web interface, so it might be more difficult to find. It seems to be largely the same binary as used by the Iocharger Pedestal charging station, however. The attacker will also need a (low privilege) account to gain access to the binary, or convince a user with such access to execute a crafted HTTP request.\n\nImpact: Critical – The attacker has full control over the charging station as the root user, and can arbitrarily add, modify and delete\nfiles and services.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:D/RE:M/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-wpr4-69wr-rf9f/GHSA-wpr4-69wr-rf9f.json b/advisories/unreviewed/2025/01/GHSA-wpr4-69wr-rf9f/GHSA-wpr4-69wr-rf9f.json new file mode 100644 index 00000000000..35460803077 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wpr4-69wr-rf9f/GHSA-wpr4-69wr-rf9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpr4-69wr-rf9f", + "modified": "2025-01-09T15:31:51Z", + "published": "2025-01-09T15:31:51Z", + "aliases": [ + "CVE-2024-7026" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024.\n\n\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7026" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1866" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T14:15:18Z" + } +} \ No newline at end of file