From 45c4a6efe0d09f3d7d32c3d1d43741e82f68ae16 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Jul 2023 12:31:52 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2j2w-8gvj-wjmj.json | 46 +++++++++++++++++ .../GHSA-2qhm-365q-v39p.json | 4 +- .../GHSA-3646-p669-xmmf.json | 38 ++++++++++++++ .../GHSA-3q3j-5m7x-chq6.json | 38 ++++++++++++++ .../GHSA-54gx-26jf-fjg6.json | 38 ++++++++++++++ .../GHSA-5f2c-c2f3-j48w.json | 38 ++++++++++++++ .../GHSA-75qj-fcp3-j9w2.json | 9 ++-- .../GHSA-7vqf-mh49-gj5h.json | 38 ++++++++++++++ .../GHSA-7x6p-wq8h-xh5w.json | 38 ++++++++++++++ .../GHSA-8m33-v7qf-p597.json | 38 ++++++++++++++ .../GHSA-8v8f-xp2h-22pm.json | 38 ++++++++++++++ .../GHSA-93qm-pj48-gqcm.json | 38 ++++++++++++++ .../GHSA-9wgp-4vcq-75qr.json | 50 +++++++++++++++++++ .../GHSA-9x5j-45q3-wgc4.json | 38 ++++++++++++++ .../GHSA-f2wh-7rgj-4wmw.json | 38 ++++++++++++++ .../GHSA-f36v-xpw4-qxf5.json | 38 ++++++++++++++ .../GHSA-f69v-gcj6-mhmx.json | 38 ++++++++++++++ .../GHSA-f824-2fpj-c8c9.json | 38 ++++++++++++++ .../GHSA-fm23-rwc2-2p82.json | 38 ++++++++++++++ .../GHSA-g2ch-vrrq-vf7w.json | 38 ++++++++++++++ .../GHSA-g5v2-xwq4-v6v3.json | 2 +- .../GHSA-g766-jqpx-q573.json | 38 ++++++++++++++ .../GHSA-hh2x-wmf9-5cgh.json | 38 ++++++++++++++ .../GHSA-hhm4-xgvr-x3rg.json | 9 ++-- .../GHSA-hqc9-64cv-8vvf.json | 38 ++++++++++++++ .../GHSA-hx3f-8w4f-f2mw.json | 38 ++++++++++++++ .../GHSA-j6x4-h5q2-mhmg.json | 38 ++++++++++++++ .../GHSA-jv2c-g9r9-8pf2.json | 38 ++++++++++++++ .../GHSA-m988-f2xj-5386.json | 38 ++++++++++++++ .../GHSA-pcw9-vp4g-qgm6.json | 38 ++++++++++++++ .../GHSA-q8r4-5w43-3vv7.json | 38 ++++++++++++++ .../GHSA-qj3v-hppm-f4vw.json | 38 ++++++++++++++ .../GHSA-qmw4-r53x-3938.json | 38 ++++++++++++++ .../GHSA-r936-4pfw-v7rj.json | 38 ++++++++++++++ .../GHSA-v3ph-x4r5-hxcp.json | 38 ++++++++++++++ .../GHSA-v7cr-mw7g-q472.json | 38 ++++++++++++++ .../GHSA-v8vq-83qq-j3vx.json | 38 ++++++++++++++ .../GHSA-w4ww-v348-8p32.json | 38 ++++++++++++++ .../GHSA-xh56-3cv8-89c9.json | 38 ++++++++++++++ 39 files changed, 1365 insertions(+), 9 deletions(-) create mode 100644 advisories/unreviewed/2023/07/GHSA-2j2w-8gvj-wjmj/GHSA-2j2w-8gvj-wjmj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3646-p669-xmmf/GHSA-3646-p669-xmmf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-3q3j-5m7x-chq6/GHSA-3q3j-5m7x-chq6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-54gx-26jf-fjg6/GHSA-54gx-26jf-fjg6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-5f2c-c2f3-j48w/GHSA-5f2c-c2f3-j48w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7vqf-mh49-gj5h/GHSA-7vqf-mh49-gj5h.json create mode 100644 advisories/unreviewed/2023/07/GHSA-7x6p-wq8h-xh5w/GHSA-7x6p-wq8h-xh5w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8m33-v7qf-p597/GHSA-8m33-v7qf-p597.json create mode 100644 advisories/unreviewed/2023/07/GHSA-8v8f-xp2h-22pm/GHSA-8v8f-xp2h-22pm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-93qm-pj48-gqcm/GHSA-93qm-pj48-gqcm.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9wgp-4vcq-75qr/GHSA-9wgp-4vcq-75qr.json create mode 100644 advisories/unreviewed/2023/07/GHSA-9x5j-45q3-wgc4/GHSA-9x5j-45q3-wgc4.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f2wh-7rgj-4wmw/GHSA-f2wh-7rgj-4wmw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f36v-xpw4-qxf5/GHSA-f36v-xpw4-qxf5.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f69v-gcj6-mhmx/GHSA-f69v-gcj6-mhmx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-f824-2fpj-c8c9/GHSA-f824-2fpj-c8c9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-fm23-rwc2-2p82/GHSA-fm23-rwc2-2p82.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g2ch-vrrq-vf7w/GHSA-g2ch-vrrq-vf7w.json create mode 100644 advisories/unreviewed/2023/07/GHSA-g766-jqpx-q573/GHSA-g766-jqpx-q573.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hh2x-wmf9-5cgh/GHSA-hh2x-wmf9-5cgh.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hqc9-64cv-8vvf/GHSA-hqc9-64cv-8vvf.json create mode 100644 advisories/unreviewed/2023/07/GHSA-hx3f-8w4f-f2mw/GHSA-hx3f-8w4f-f2mw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-j6x4-h5q2-mhmg/GHSA-j6x4-h5q2-mhmg.json create mode 100644 advisories/unreviewed/2023/07/GHSA-jv2c-g9r9-8pf2/GHSA-jv2c-g9r9-8pf2.json create mode 100644 advisories/unreviewed/2023/07/GHSA-m988-f2xj-5386/GHSA-m988-f2xj-5386.json create mode 100644 advisories/unreviewed/2023/07/GHSA-pcw9-vp4g-qgm6/GHSA-pcw9-vp4g-qgm6.json create mode 100644 advisories/unreviewed/2023/07/GHSA-q8r4-5w43-3vv7/GHSA-q8r4-5w43-3vv7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qj3v-hppm-f4vw/GHSA-qj3v-hppm-f4vw.json create mode 100644 advisories/unreviewed/2023/07/GHSA-qmw4-r53x-3938/GHSA-qmw4-r53x-3938.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r936-4pfw-v7rj/GHSA-r936-4pfw-v7rj.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v3ph-x4r5-hxcp/GHSA-v3ph-x4r5-hxcp.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v7cr-mw7g-q472/GHSA-v7cr-mw7g-q472.json create mode 100644 advisories/unreviewed/2023/07/GHSA-v8vq-83qq-j3vx/GHSA-v8vq-83qq-j3vx.json create mode 100644 advisories/unreviewed/2023/07/GHSA-w4ww-v348-8p32/GHSA-w4ww-v348-8p32.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xh56-3cv8-89c9/GHSA-xh56-3cv8-89c9.json diff --git a/advisories/unreviewed/2023/07/GHSA-2j2w-8gvj-wjmj/GHSA-2j2w-8gvj-wjmj.json b/advisories/unreviewed/2023/07/GHSA-2j2w-8gvj-wjmj/GHSA-2j2w-8gvj-wjmj.json new file mode 100644 index 00000000000..d0b42024e4d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-2j2w-8gvj-wjmj/GHSA-2j2w-8gvj-wjmj.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2j2w-8gvj-wjmj", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-3269" + ], + "details": "A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3269" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-3269" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2215268" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/07/05/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json b/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json index 6284e11e7ee..7cbfc44d75f 100644 --- a/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json +++ b/advisories/unreviewed/2023/07/GHSA-2qhm-365q-v39p/GHSA-2qhm-365q-v39p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qhm-365q-v39p", - "modified": "2023-07-05T15:30:25Z", + "modified": "2023-07-11T12:30:34Z", "published": "2023-07-05T15:30:25Z", "aliases": [ "CVE-2023-35978" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-3646-p669-xmmf/GHSA-3646-p669-xmmf.json b/advisories/unreviewed/2023/07/GHSA-3646-p669-xmmf/GHSA-3646-p669-xmmf.json new file mode 100644 index 00000000000..5baed957f94 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3646-p669-xmmf/GHSA-3646-p669-xmmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3646-p669-xmmf", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37247" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21138)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37247" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-3q3j-5m7x-chq6/GHSA-3q3j-5m7x-chq6.json b/advisories/unreviewed/2023/07/GHSA-3q3j-5m7x-chq6/GHSA-3q3j-5m7x-chq6.json new file mode 100644 index 00000000000..e8e4b7d9e39 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3q3j-5m7x-chq6/GHSA-3q3j-5m7x-chq6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q3j-5m7x-chq6", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-29131" + ], + "details": "A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH configuration. This could allow an attacker to bypass network isolation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29131" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-54gx-26jf-fjg6/GHSA-54gx-26jf-fjg6.json b/advisories/unreviewed/2023/07/GHSA-54gx-26jf-fjg6/GHSA-54gx-26jf-fjg6.json new file mode 100644 index 00000000000..39bb0b4eb1c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-54gx-26jf-fjg6/GHSA-54gx-26jf-fjg6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54gx-26jf-fjg6", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37246" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21109)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37246" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-5f2c-c2f3-j48w/GHSA-5f2c-c2f3-j48w.json b/advisories/unreviewed/2023/07/GHSA-5f2c-c2f3-j48w/GHSA-5f2c-c2f3-j48w.json new file mode 100644 index 00000000000..a68fafac0b0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-5f2c-c2f3-j48w/GHSA-5f2c-c2f3-j48w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2c-c2f3-j48w", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37375" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to stack-based buffer overflow while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21060)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37375" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json b/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json index 90a7c84067a..e50fcf71515 100644 --- a/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json +++ b/advisories/unreviewed/2023/07/GHSA-75qj-fcp3-j9w2/GHSA-75qj-fcp3-j9w2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-75qj-fcp3-j9w2", - "modified": "2023-07-05T09:30:20Z", + "modified": "2023-07-11T12:30:34Z", "published": "2023-07-05T09:30:20Z", "aliases": [ "CVE-2023-37201" ], "details": "An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-7vqf-mh49-gj5h/GHSA-7vqf-mh49-gj5h.json b/advisories/unreviewed/2023/07/GHSA-7vqf-mh49-gj5h/GHSA-7vqf-mh49-gj5h.json new file mode 100644 index 00000000000..9c284c0cfa3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7vqf-mh49-gj5h/GHSA-7vqf-mh49-gj5h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vqf-mh49-gj5h", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-37391" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37391" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wordpress-mobile-pack/wordpress-wordpress-mobile-pack-plugin-3-4-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-7x6p-wq8h-xh5w/GHSA-7x6p-wq8h-xh5w.json b/advisories/unreviewed/2023/07/GHSA-7x6p-wq8h-xh5w/GHSA-7x6p-wq8h-xh5w.json new file mode 100644 index 00000000000..0df4c04ef9a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-7x6p-wq8h-xh5w/GHSA-7x6p-wq8h-xh5w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x6p-wq8h-xh5w", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-23671" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <= 1.1.9.7 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23671" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/slider-slideshow/wordpress-layer-slider-plugin-1-1-9-6-cross-site-request-forgery-csrf-leading-to-post-page-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8m33-v7qf-p597/GHSA-8m33-v7qf-p597.json b/advisories/unreviewed/2023/07/GHSA-8m33-v7qf-p597/GHSA-8m33-v7qf-p597.json new file mode 100644 index 00000000000..a78c061874d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8m33-v7qf-p597/GHSA-8m33-v7qf-p597.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m33-v7qf-p597", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-35921" + ], + "details": "A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted Ethernet frames sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35921" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-561322.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-8v8f-xp2h-22pm/GHSA-8v8f-xp2h-22pm.json b/advisories/unreviewed/2023/07/GHSA-8v8f-xp2h-22pm/GHSA-8v8f-xp2h-22pm.json new file mode 100644 index 00000000000..ddd29deb9f9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-8v8f-xp2h-22pm/GHSA-8v8f-xp2h-22pm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v8f-xp2h-22pm", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-35920" + ], + "details": "A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted IP packets sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35920" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-561322.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-93qm-pj48-gqcm/GHSA-93qm-pj48-gqcm.json b/advisories/unreviewed/2023/07/GHSA-93qm-pj48-gqcm/GHSA-93qm-pj48-gqcm.json new file mode 100644 index 00000000000..a32882ebd7e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-93qm-pj48-gqcm/GHSA-93qm-pj48-gqcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93qm-pj48-gqcm", + "modified": "2023-07-11T12:30:34Z", + "published": "2023-07-11T12:30:34Z", + "aliases": [ + "CVE-2022-29561" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29561" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9wgp-4vcq-75qr/GHSA-9wgp-4vcq-75qr.json b/advisories/unreviewed/2023/07/GHSA-9wgp-4vcq-75qr/GHSA-9wgp-4vcq-75qr.json new file mode 100644 index 00000000000..0c94e4f363b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9wgp-4vcq-75qr/GHSA-9wgp-4vcq-75qr.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wgp-4vcq-75qr", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-1672" + ], + "details": "A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-1672" + }, + { + "type": "WEB", + "url": "https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-1672" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2180999" + }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/06/15/1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-9x5j-45q3-wgc4/GHSA-9x5j-45q3-wgc4.json b/advisories/unreviewed/2023/07/GHSA-9x5j-45q3-wgc4/GHSA-9x5j-45q3-wgc4.json new file mode 100644 index 00000000000..03471d61f11 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-9x5j-45q3-wgc4/GHSA-9x5j-45q3-wgc4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x5j-45q3-wgc4", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36693" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez WP RSS Images plugin <= 1.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36693" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-rss-images/wordpress-wp-rss-images-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f2wh-7rgj-4wmw/GHSA-f2wh-7rgj-4wmw.json b/advisories/unreviewed/2023/07/GHSA-f2wh-7rgj-4wmw/GHSA-f2wh-7rgj-4wmw.json new file mode 100644 index 00000000000..65b900c145a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f2wh-7rgj-4wmw/GHSA-f2wh-7rgj-4wmw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2wh-7rgj-4wmw", + "modified": "2023-07-11T12:30:34Z", + "published": "2023-07-11T12:30:34Z", + "aliases": [ + "CVE-2022-29562" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). Affected devices do not properly handle malformed HTTP packets. This could allow an unauthenticated remote attacker to send a malformed HTTP packet causing certain functions to fail in a controlled manner.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29562" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f36v-xpw4-qxf5/GHSA-f36v-xpw4-qxf5.json b/advisories/unreviewed/2023/07/GHSA-f36v-xpw4-qxf5/GHSA-f36v-xpw4-qxf5.json new file mode 100644 index 00000000000..6deef5ea30a --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f36v-xpw4-qxf5/GHSA-f36v-xpw4-qxf5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f36v-xpw4-qxf5", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36389" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. The malformed value is reflected\ndirectly in the response without sanitization while throwing an “invalid path” error.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36389" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f69v-gcj6-mhmx/GHSA-f69v-gcj6-mhmx.json b/advisories/unreviewed/2023/07/GHSA-f69v-gcj6-mhmx/GHSA-f69v-gcj6-mhmx.json new file mode 100644 index 00000000000..eb63b25211d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f69v-gcj6-mhmx/GHSA-f69v-gcj6-mhmx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f69v-gcj6-mhmx", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36750" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The software-upgrade Url parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36750" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-f824-2fpj-c8c9/GHSA-f824-2fpj-c8c9.json b/advisories/unreviewed/2023/07/GHSA-f824-2fpj-c8c9/GHSA-f824-2fpj-c8c9.json new file mode 100644 index 00000000000..40688f7faf9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-f824-2fpj-c8c9/GHSA-f824-2fpj-c8c9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f824-2fpj-c8c9", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36754" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The SCEP server configuration URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36754" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-fm23-rwc2-2p82/GHSA-fm23-rwc2-2p82.json b/advisories/unreviewed/2023/07/GHSA-fm23-rwc2-2p82/GHSA-fm23-rwc2-2p82.json new file mode 100644 index 00000000000..964043efcf0 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-fm23-rwc2-2p82/GHSA-fm23-rwc2-2p82.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm23-rwc2-2p82", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2022-31810" + ], + "details": "A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a stack-based buffer overflow.\n\nThis could allow an unauthenticated remote attacker to crash the server application, creating a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31810" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-924149.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g2ch-vrrq-vf7w/GHSA-g2ch-vrrq-vf7w.json b/advisories/unreviewed/2023/07/GHSA-g2ch-vrrq-vf7w/GHSA-g2ch-vrrq-vf7w.json new file mode 100644 index 00000000000..34f5095c9e4 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g2ch-vrrq-vf7w/GHSA-g2ch-vrrq-vf7w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2ch-vrrq-vf7w", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36521" + ], + "details": "A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). The result synchronization server of the affected products contains a\nvulnerability that may lead to a denial of service condition. An attacker may\ncause a denial of service situation of all socket-based communication of the\naffected products if the result server is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36521" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-561322.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-g5v2-xwq4-v6v3/GHSA-g5v2-xwq4-v6v3.json b/advisories/unreviewed/2023/07/GHSA-g5v2-xwq4-v6v3/GHSA-g5v2-xwq4-v6v3.json index 0ec45671cb8..189e83bc202 100644 --- a/advisories/unreviewed/2023/07/GHSA-g5v2-xwq4-v6v3/GHSA-g5v2-xwq4-v6v3.json +++ b/advisories/unreviewed/2023/07/GHSA-g5v2-xwq4-v6v3/GHSA-g5v2-xwq4-v6v3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-g766-jqpx-q573/GHSA-g766-jqpx-q573.json b/advisories/unreviewed/2023/07/GHSA-g766-jqpx-q573/GHSA-g766-jqpx-q573.json new file mode 100644 index 00000000000..cf87f3ec04c --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-g766-jqpx-q573/GHSA-g766-jqpx-q573.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g766-jqpx-q573", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37248" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted PAR file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21155)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37248" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hh2x-wmf9-5cgh/GHSA-hh2x-wmf9-5cgh.json b/advisories/unreviewed/2023/07/GHSA-hh2x-wmf9-5cgh/GHSA-hh2x-wmf9-5cgh.json new file mode 100644 index 00000000000..336fe22d548 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hh2x-wmf9-5cgh/GHSA-hh2x-wmf9-5cgh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh2x-wmf9-5cgh", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-35780" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andy Whalen Galleria plugin <= 1.0.3 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35780" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/galleria/wordpress-galleria-plugin-1-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json b/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json index 2b6cb393a39..d898852ee64 100644 --- a/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json +++ b/advisories/unreviewed/2023/07/GHSA-hhm4-xgvr-x3rg/GHSA-hhm4-xgvr-x3rg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hhm4-xgvr-x3rg", - "modified": "2023-07-05T09:30:20Z", + "modified": "2023-07-11T12:30:34Z", "published": "2023-07-05T09:30:20Z", "aliases": [ "CVE-2023-37202" ], "details": "Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-hqc9-64cv-8vvf/GHSA-hqc9-64cv-8vvf.json b/advisories/unreviewed/2023/07/GHSA-hqc9-64cv-8vvf/GHSA-hqc9-64cv-8vvf.json new file mode 100644 index 00000000000..5eea52a5f00 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hqc9-64cv-8vvf/GHSA-hqc9-64cv-8vvf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqc9-64cv-8vvf", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-29130" + ], + "details": "A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete device control.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29130" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-313488.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-hx3f-8w4f-f2mw/GHSA-hx3f-8w4f-f2mw.json b/advisories/unreviewed/2023/07/GHSA-hx3f-8w4f-f2mw/GHSA-hx3f-8w4f-f2mw.json new file mode 100644 index 00000000000..956cd23c0b3 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-hx3f-8w4f-f2mw/GHSA-hx3f-8w4f-f2mw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx3f-8w4f-f2mw", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36386" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. The value is reflected in the response without sanitization while throwing an\n“invalid params element name” error on the get_elements parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36386" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-j6x4-h5q2-mhmg/GHSA-j6x4-h5q2-mhmg.json b/advisories/unreviewed/2023/07/GHSA-j6x4-h5q2-mhmg/GHSA-j6x4-h5q2-mhmg.json new file mode 100644 index 00000000000..38e7eb7a7fc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-j6x4-h5q2-mhmg/GHSA-j6x4-h5q2-mhmg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6x4-h5q2-mhmg", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36748" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The affected devices are configured to offer weak ciphers by default. This could allow an unauthorized attacker in a man-in-the-middle position to read and modify any data\npassed over to and from the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36748" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-jv2c-g9r9-8pf2/GHSA-jv2c-g9r9-8pf2.json b/advisories/unreviewed/2023/07/GHSA-jv2c-g9r9-8pf2/GHSA-jv2c-g9r9-8pf2.json new file mode 100644 index 00000000000..bd82b316a4e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-jv2c-g9r9-8pf2/GHSA-jv2c-g9r9-8pf2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv2c-g9r9-8pf2", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37376" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application contains a type confusion vulnerability while parsing STP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21051)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37376" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-m988-f2xj-5386/GHSA-m988-f2xj-5386.json b/advisories/unreviewed/2023/07/GHSA-m988-f2xj-5386/GHSA-m988-f2xj-5386.json new file mode 100644 index 00000000000..ed84e9e3c57 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-m988-f2xj-5386/GHSA-m988-f2xj-5386.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m988-f2xj-5386", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36751" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The install-app URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36751" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-pcw9-vp4g-qgm6/GHSA-pcw9-vp4g-qgm6.json b/advisories/unreviewed/2023/07/GHSA-pcw9-vp4g-qgm6/GHSA-pcw9-vp4g-qgm6.json new file mode 100644 index 00000000000..1edec462bc9 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-pcw9-vp4g-qgm6/GHSA-pcw9-vp4g-qgm6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcw9-vp4g-qgm6", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36749" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36749" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-q8r4-5w43-3vv7/GHSA-q8r4-5w43-3vv7.json b/advisories/unreviewed/2023/07/GHSA-q8r4-5w43-3vv7/GHSA-q8r4-5w43-3vv7.json new file mode 100644 index 00000000000..c5329761855 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-q8r4-5w43-3vv7/GHSA-q8r4-5w43-3vv7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8r4-5w43-3vv7", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36752" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The upgrade-app URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36752" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qj3v-hppm-f4vw/GHSA-qj3v-hppm-f4vw.json b/advisories/unreviewed/2023/07/GHSA-qj3v-hppm-f4vw/GHSA-qj3v-hppm-f4vw.json new file mode 100644 index 00000000000..631093d25b8 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qj3v-hppm-f4vw/GHSA-qj3v-hppm-f4vw.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj3v-hppm-f4vw", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-37374" + ], + "details": "A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to stack-based buffer overflow while parsing specially crafted STP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21054)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37374" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-764801.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-qmw4-r53x-3938/GHSA-qmw4-r53x-3938.json b/advisories/unreviewed/2023/07/GHSA-qmw4-r53x-3938/GHSA-qmw4-r53x-3938.json new file mode 100644 index 00000000000..752c24eb1f6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-qmw4-r53x-3938/GHSA-qmw4-r53x-3938.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmw4-r53x-3938", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36753" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The uninstall-app App-name parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36753" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r936-4pfw-v7rj/GHSA-r936-4pfw-v7rj.json b/advisories/unreviewed/2023/07/GHSA-r936-4pfw-v7rj/GHSA-r936-4pfw-v7rj.json new file mode 100644 index 00000000000..8ed1aa242c6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r936-4pfw-v7rj/GHSA-r936-4pfw-v7rj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r936-4pfw-v7rj", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-35047" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <= 1.3.6 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35047" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/all-bootstrap-blocks/wordpress-all-bootstrap-blocks-plugin-1-3-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v3ph-x4r5-hxcp/GHSA-v3ph-x4r5-hxcp.json b/advisories/unreviewed/2023/07/GHSA-v3ph-x4r5-hxcp/GHSA-v3ph-x4r5-hxcp.json new file mode 100644 index 00000000000..68342b2e748 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v3ph-x4r5-hxcp/GHSA-v3ph-x4r5-hxcp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3ph-x4r5-hxcp", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36755" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The SCEP CA Certificate Name parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36755" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v7cr-mw7g-q472/GHSA-v7cr-mw7g-q472.json b/advisories/unreviewed/2023/07/GHSA-v7cr-mw7g-q472/GHSA-v7cr-mw7g-q472.json new file mode 100644 index 00000000000..a136d589204 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v7cr-mw7g-q472/GHSA-v7cr-mw7g-q472.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7cr-mw7g-q472", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-35778" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/recent-posts-slider/wordpress-recent-posts-slider-plugin-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-v8vq-83qq-j3vx/GHSA-v8vq-83qq-j3vx.json b/advisories/unreviewed/2023/07/GHSA-v8vq-83qq-j3vx/GHSA-v8vq-83qq-j3vx.json new file mode 100644 index 00000000000..b368b40b73f --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-v8vq-83qq-j3vx/GHSA-v8vq-83qq-j3vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8vq-83qq-j3vx", + "modified": "2023-07-11T12:30:35Z", + "published": "2023-07-11T12:30:35Z", + "aliases": [ + "CVE-2023-36390" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected application that could allow an attacker to execute malicious javascript code by tricking users into accessing a malicious link. The value is reflected in the response\nwithout sanitization while throwing an “invalid params element name” error on the action parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36390" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-146325.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-w4ww-v348-8p32/GHSA-w4ww-v348-8p32.json b/advisories/unreviewed/2023/07/GHSA-w4ww-v348-8p32/GHSA-w4ww-v348-8p32.json new file mode 100644 index 00000000000..ca8eff937da --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-w4ww-v348-8p32/GHSA-w4ww-v348-8p32.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4ww-v348-8p32", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-34185" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34185" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wordpress-nextgen-galleryview/wordpress-wordpress-nextgen-galleryview-plugin-0-5-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xh56-3cv8-89c9/GHSA-xh56-3cv8-89c9.json b/advisories/unreviewed/2023/07/GHSA-xh56-3cv8-89c9/GHSA-xh56-3cv8-89c9.json new file mode 100644 index 00000000000..a05bcf05ccc --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xh56-3cv8-89c9/GHSA-xh56-3cv8-89c9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh56-3cv8-89c9", + "modified": "2023-07-11T12:30:36Z", + "published": "2023-07-11T12:30:36Z", + "aliases": [ + "CVE-2023-36687" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/menubar/wordpress-menubar-plugin-5-8-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file