From 49eb4f92f5969b87930acb9d71ff02095951348a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Oct 2024 00:32:41 +0000 Subject: [PATCH] Publish Advisories GHSA-5f95-9ghj-fh4j GHSA-9g8p-26mc-3hm7 GHSA-mcvc-882q-2wfq GHSA-xmpm-8vxp-qxhh --- .../GHSA-5f95-9ghj-fh4j.json | 54 +++++++++++++++++ .../GHSA-9g8p-26mc-3hm7.json | 58 +++++++++++++++++++ .../GHSA-mcvc-882q-2wfq.json | 58 +++++++++++++++++++ .../GHSA-xmpm-8vxp-qxhh.json | 58 +++++++++++++++++++ 4 files changed, 228 insertions(+) create mode 100644 advisories/unreviewed/2024/10/GHSA-5f95-9ghj-fh4j/GHSA-5f95-9ghj-fh4j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9g8p-26mc-3hm7/GHSA-9g8p-26mc-3hm7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mcvc-882q-2wfq/GHSA-mcvc-882q-2wfq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xmpm-8vxp-qxhh/GHSA-xmpm-8vxp-qxhh.json diff --git a/advisories/unreviewed/2024/10/GHSA-5f95-9ghj-fh4j/GHSA-5f95-9ghj-fh4j.json b/advisories/unreviewed/2024/10/GHSA-5f95-9ghj-fh4j/GHSA-5f95-9ghj-fh4j.json new file mode 100644 index 00000000000..00ed6a15af7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5f95-9ghj-fh4j/GHSA-5f95-9ghj-fh4j.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f95-9ghj-fh4j", + "modified": "2024-10-07T00:31:02Z", + "published": "2024-10-07T00:31:02Z", + "aliases": [ + "CVE-2024-9560" + ], + "details": "A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelogs. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9560" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/38f64855-27ec-4170-ac78-f29ca595901e?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279368" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279368" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.414475" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-06T22:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9g8p-26mc-3hm7/GHSA-9g8p-26mc-3hm7.json b/advisories/unreviewed/2024/10/GHSA-9g8p-26mc-3hm7/GHSA-9g8p-26mc-3hm7.json new file mode 100644 index 00000000000..f817b6433a0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9g8p-26mc-3hm7/GHSA-9g8p-26mc-3hm7.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g8p-26mc-3hm7", + "modified": "2024-10-07T00:31:03Z", + "published": "2024-10-07T00:31:03Z", + "aliases": [ + "CVE-2024-9563" + ], + "details": "A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. The manipulation of the argument webpage leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9563" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-605L/formWlanSetup_Wizard.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279371" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279371" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413922" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-07T00:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mcvc-882q-2wfq/GHSA-mcvc-882q-2wfq.json b/advisories/unreviewed/2024/10/GHSA-mcvc-882q-2wfq/GHSA-mcvc-882q-2wfq.json new file mode 100644 index 00000000000..b49e88bd115 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mcvc-882q-2wfq/GHSA-mcvc-882q-2wfq.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcvc-882q-2wfq", + "modified": "2024-10-07T00:31:03Z", + "published": "2024-10-07T00:31:03Z", + "aliases": [ + "CVE-2024-9562" + ], + "details": "A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9562" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-605L/formSetWizard.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279370" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279370" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413921" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-06T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xmpm-8vxp-qxhh/GHSA-xmpm-8vxp-qxhh.json b/advisories/unreviewed/2024/10/GHSA-xmpm-8vxp-qxhh/GHSA-xmpm-8vxp-qxhh.json new file mode 100644 index 00000000000..12a2f1566c5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xmpm-8vxp-qxhh/GHSA-xmpm-8vxp-qxhh.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmpm-8vxp-qxhh", + "modified": "2024-10-07T00:31:03Z", + "published": "2024-10-07T00:31:03Z", + "aliases": [ + "CVE-2024-9561" + ], + "details": "A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9561" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-605L/formSetWAN_Wizard.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.279369" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.279369" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.413920" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-06T23:15:12Z" + } +} \ No newline at end of file