diff --git a/advisories/unreviewed/2022/12/GHSA-v7cj-vm62-r38r/GHSA-v7cj-vm62-r38r.json b/advisories/unreviewed/2022/12/GHSA-v7cj-vm62-r38r/GHSA-v7cj-vm62-r38r.json index 6b19c9aaa47..19ab27b690c 100644 --- a/advisories/unreviewed/2022/12/GHSA-v7cj-vm62-r38r/GHSA-v7cj-vm62-r38r.json +++ b/advisories/unreviewed/2022/12/GHSA-v7cj-vm62-r38r/GHSA-v7cj-vm62-r38r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7cj-vm62-r38r", - "modified": "2022-12-19T15:30:29Z", + "modified": "2024-08-13T09:30:50Z", "published": "2022-12-13T18:30:34Z", "aliases": [ "CVE-2022-46143" @@ -21,6 +21,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46143" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-180704.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-413565.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf" diff --git a/advisories/unreviewed/2023/02/GHSA-5qx2-5w4h-wgr8/GHSA-5qx2-5w4h-wgr8.json b/advisories/unreviewed/2023/02/GHSA-5qx2-5w4h-wgr8/GHSA-5qx2-5w4h-wgr8.json index 2ff11224b07..b0f18497c74 100644 --- a/advisories/unreviewed/2023/02/GHSA-5qx2-5w4h-wgr8/GHSA-5qx2-5w4h-wgr8.json +++ b/advisories/unreviewed/2023/02/GHSA-5qx2-5w4h-wgr8/GHSA-5qx2-5w4h-wgr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qx2-5w4h-wgr8", - "modified": "2023-02-22T18:30:34Z", + "modified": "2024-08-13T09:30:50Z", "published": "2023-02-14T12:30:26Z", "aliases": [ "CVE-2022-35868" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35868" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-640968.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-640968.pdf" diff --git a/advisories/unreviewed/2023/04/GHSA-pfr5-cpm3-g35v/GHSA-pfr5-cpm3-g35v.json b/advisories/unreviewed/2023/04/GHSA-pfr5-cpm3-g35v/GHSA-pfr5-cpm3-g35v.json index 488df15358a..570cd2e6b21 100644 --- a/advisories/unreviewed/2023/04/GHSA-pfr5-cpm3-g35v/GHSA-pfr5-cpm3-g35v.json +++ b/advisories/unreviewed/2023/04/GHSA-pfr5-cpm3-g35v/GHSA-pfr5-cpm3-g35v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pfr5-cpm3-g35v", - "modified": "2023-04-11T12:30:26Z", + "modified": "2024-08-13T09:30:50Z", "published": "2023-04-11T12:30:26Z", "aliases": [ "CVE-2023-26293" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26293" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-116924.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-116924.pdf" diff --git a/advisories/unreviewed/2023/08/GHSA-85h8-9x77-pg3v/GHSA-85h8-9x77-pg3v.json b/advisories/unreviewed/2023/08/GHSA-85h8-9x77-pg3v/GHSA-85h8-9x77-pg3v.json index ba2d7698c49..2077db69b63 100644 --- a/advisories/unreviewed/2023/08/GHSA-85h8-9x77-pg3v/GHSA-85h8-9x77-pg3v.json +++ b/advisories/unreviewed/2023/08/GHSA-85h8-9x77-pg3v/GHSA-85h8-9x77-pg3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85h8-9x77-pg3v", - "modified": "2024-06-11T12:31:00Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-08-08T12:30:20Z", "aliases": [ "CVE-2023-38529" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-c48j-w2fx-98qq/GHSA-c48j-w2fx-98qq.json b/advisories/unreviewed/2023/08/GHSA-c48j-w2fx-98qq/GHSA-c48j-w2fx-98qq.json index 8acb2c9eed3..37ea06bc088 100644 --- a/advisories/unreviewed/2023/08/GHSA-c48j-w2fx-98qq/GHSA-c48j-w2fx-98qq.json +++ b/advisories/unreviewed/2023/08/GHSA-c48j-w2fx-98qq/GHSA-c48j-w2fx-98qq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c48j-w2fx-98qq", - "modified": "2024-06-11T12:31:00Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-08-08T12:30:20Z", "aliases": [ "CVE-2023-38527" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/08/GHSA-wj8f-wx2j-wjcg/GHSA-wj8f-wx2j-wjcg.json b/advisories/unreviewed/2023/08/GHSA-wj8f-wx2j-wjcg/GHSA-wj8f-wx2j-wjcg.json index 90ad183a28e..45a293dc943 100644 --- a/advisories/unreviewed/2023/08/GHSA-wj8f-wx2j-wjcg/GHSA-wj8f-wx2j-wjcg.json +++ b/advisories/unreviewed/2023/08/GHSA-wj8f-wx2j-wjcg/GHSA-wj8f-wx2j-wjcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wj8f-wx2j-wjcg", - "modified": "2024-06-11T12:31:00Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-08-08T12:30:20Z", "aliases": [ "CVE-2023-38531" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json b/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json index ca6f20497ba..7260d52e5a7 100644 --- a/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json +++ b/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-282g-wxjw-75vj", - "modified": "2024-02-13T09:30:28Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44320" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44320" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-068047.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-180704.html" diff --git a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json index 2b1dd4c4304..b8d9143ce2a 100644 --- a/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json +++ b/advisories/unreviewed/2023/11/GHSA-86gv-6g4q-x856/GHSA-86gv-6g4q-x856.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-86gv-6g4q-x856", - "modified": "2024-06-11T09:30:56Z", + "modified": "2024-08-13T09:30:52Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44373" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2023/11/GHSA-w4f6-7r85-9m86/GHSA-w4f6-7r85-9m86.json b/advisories/unreviewed/2023/11/GHSA-w4f6-7r85-9m86/GHSA-w4f6-7r85-9m86.json index 601c51248d1..ca782ad748c 100644 --- a/advisories/unreviewed/2023/11/GHSA-w4f6-7r85-9m86/GHSA-w4f6-7r85-9m86.json +++ b/advisories/unreviewed/2023/11/GHSA-w4f6-7r85-9m86/GHSA-w4f6-7r85-9m86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4f6-7r85-9m86", - "modified": "2024-03-12T12:30:47Z", + "modified": "2024-08-13T09:30:52Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44321" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -21,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44321" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-087301.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-180704.html" diff --git a/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json b/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json index 3b0422f458a..4a0a62dcd85 100644 --- a/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json +++ b/advisories/unreviewed/2023/12/GHSA-395m-pvc6-8rvm/GHSA-395m-pvc6-8rvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-395m-pvc6-8rvm", - "modified": "2024-05-14T18:30:34Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46283" diff --git a/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json b/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json index c34867c9af9..4fda6db5127 100644 --- a/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json +++ b/advisories/unreviewed/2023/12/GHSA-84mm-xgw8-mv4q/GHSA-84mm-xgw8-mv4q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-84mm-xgw8-mv4q", - "modified": "2024-05-14T18:30:34Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46285" diff --git a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json index a0279cf0fed..d2dcae6b2a5 100644 --- a/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json +++ b/advisories/unreviewed/2023/12/GHSA-9qvw-gvq6-g569/GHSA-9qvw-gvq6-g569.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qvw-gvq6-g569", - "modified": "2024-05-14T18:30:33Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-12-12T12:30:53Z", "aliases": [ "CVE-2023-46281" diff --git a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json index 82de18d8e54..22073b9cc2c 100644 --- a/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json +++ b/advisories/unreviewed/2023/12/GHSA-f2hj-x395-x532/GHSA-f2hj-x395-x532.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2hj-x395-x532", - "modified": "2024-05-14T18:30:34Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46284" diff --git a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json index c4ed1b9ee86..f8815e052cc 100644 --- a/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json +++ b/advisories/unreviewed/2023/12/GHSA-fmr5-j3hh-jpg4/GHSA-fmr5-j3hh-jpg4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fmr5-j3hh-jpg4", - "modified": "2024-05-14T18:30:34Z", + "modified": "2024-08-13T09:30:51Z", "published": "2023-12-12T12:30:54Z", "aliases": [ "CVE-2023-46282" diff --git a/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json b/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json index 8a17b9315cd..5b100af1393 100644 --- a/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json +++ b/advisories/unreviewed/2024/04/GHSA-c732-w2pw-3g36/GHSA-c732-w2pw-3g36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c732-w2pw-3g36", - "modified": "2024-06-11T12:31:01Z", + "modified": "2024-08-13T09:30:51Z", "published": "2024-04-09T09:31:11Z", "aliases": [ "CVE-2024-26275" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json b/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json index c133ca3105c..39386e25307 100644 --- a/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json +++ b/advisories/unreviewed/2024/04/GHSA-gx7g-x5pw-4h97/GHSA-gx7g-x5pw-4h97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx7g-x5pw-4h97", - "modified": "2024-06-11T12:31:01Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-04-09T09:31:11Z", "aliases": [ "CVE-2024-26277" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json b/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json index a2280dcab7c..5b53009b46a 100644 --- a/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json +++ b/advisories/unreviewed/2024/04/GHSA-j254-m7h5-8jrj/GHSA-j254-m7h5-8jrj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j254-m7h5-8jrj", - "modified": "2024-06-11T12:31:01Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-04-09T09:31:11Z", "aliases": [ "CVE-2024-26276" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ diff --git a/advisories/unreviewed/2024/05/GHSA-3h7r-9fxc-5mxj/GHSA-3h7r-9fxc-5mxj.json b/advisories/unreviewed/2024/05/GHSA-3h7r-9fxc-5mxj/GHSA-3h7r-9fxc-5mxj.json index 62f2173420d..0bf0ef9caf2 100644 --- a/advisories/unreviewed/2024/05/GHSA-3h7r-9fxc-5mxj/GHSA-3h7r-9fxc-5mxj.json +++ b/advisories/unreviewed/2024/05/GHSA-3h7r-9fxc-5mxj/GHSA-3h7r-9fxc-5mxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3h7r-9fxc-5mxj", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32635" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -24,6 +28,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-046364.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-856475.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-g3gv-9xvr-p3r6/GHSA-g3gv-9xvr-p3r6.json b/advisories/unreviewed/2024/05/GHSA-g3gv-9xvr-p3r6/GHSA-g3gv-9xvr-p3r6.json index 681ab9fcfe8..bd745523a00 100644 --- a/advisories/unreviewed/2024/05/GHSA-g3gv-9xvr-p3r6/GHSA-g3gv-9xvr-p3r6.json +++ b/advisories/unreviewed/2024/05/GHSA-g3gv-9xvr-p3r6/GHSA-g3gv-9xvr-p3r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g3gv-9xvr-p3r6", - "modified": "2024-07-09T12:30:55Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-05-14T18:30:58Z", "aliases": [ "CVE-2023-46280" @@ -25,6 +25,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46280" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-962515.html" diff --git a/advisories/unreviewed/2024/05/GHSA-mwmv-6v63-763h/GHSA-mwmv-6v63-763h.json b/advisories/unreviewed/2024/05/GHSA-mwmv-6v63-763h/GHSA-mwmv-6v63-763h.json index 8e56f703af1..29245014a10 100644 --- a/advisories/unreviewed/2024/05/GHSA-mwmv-6v63-763h/GHSA-mwmv-6v63-763h.json +++ b/advisories/unreviewed/2024/05/GHSA-mwmv-6v63-763h/GHSA-mwmv-6v63-763h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mwmv-6v63-763h", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32636" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -24,6 +28,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-046364.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-856475.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-x3j5-gf6q-9cm2/GHSA-x3j5-gf6q-9cm2.json b/advisories/unreviewed/2024/05/GHSA-x3j5-gf6q-9cm2/GHSA-x3j5-gf6q-9cm2.json index 2a3f32c8e17..03a50654b75 100644 --- a/advisories/unreviewed/2024/05/GHSA-x3j5-gf6q-9cm2/GHSA-x3j5-gf6q-9cm2.json +++ b/advisories/unreviewed/2024/05/GHSA-x3j5-gf6q-9cm2/GHSA-x3j5-gf6q-9cm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3j5-gf6q-9cm2", - "modified": "2024-05-14T18:31:00Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-05-14T18:31:00Z", "aliases": [ "CVE-2024-32637" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [ @@ -24,6 +28,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-046364.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-856475.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json b/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json index fa165dd3f85..e000c229d34 100644 --- a/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json +++ b/advisories/unreviewed/2024/08/GHSA-4h47-46m8-cx7g/GHSA-4h47-46m8-cx7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h47-46m8-cx7g", - "modified": "2024-08-02T12:31:43Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-38879" diff --git a/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json b/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json index 1b8b858252b..1ce12517a0f 100644 --- a/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json +++ b/advisories/unreviewed/2024/08/GHSA-5f2h-gxrx-j654/GHSA-5f2h-gxrx-j654.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5f2h-gxrx-j654", - "modified": "2024-08-02T12:31:43Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-38877" diff --git a/advisories/unreviewed/2024/08/GHSA-679x-9c34-9qg2/GHSA-679x-9c34-9qg2.json b/advisories/unreviewed/2024/08/GHSA-679x-9c34-9qg2/GHSA-679x-9c34-9qg2.json new file mode 100644 index 00000000000..16ae7f6b7cd --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-679x-9c34-9qg2/GHSA-679x-9c34-9qg2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-679x-9c34-9qg2", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41682" + ], + "details": "A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated remote attacker to conduct brute force attacks against legitimate user passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41682" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-720392.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json b/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json index 2fa3710b05b..fcfaf855c31 100644 --- a/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json +++ b/advisories/unreviewed/2024/08/GHSA-6cjc-w4j3-jjh8/GHSA-6cjc-w4j3-jjh8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cjc-w4j3-jjh8", - "modified": "2024-08-02T12:31:43Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-38878" diff --git a/advisories/unreviewed/2024/08/GHSA-77vg-gpvf-jj6q/GHSA-77vg-gpvf-jj6q.json b/advisories/unreviewed/2024/08/GHSA-77vg-gpvf-jj6q/GHSA-77vg-gpvf-jj6q.json new file mode 100644 index 00000000000..72d5d449556 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-77vg-gpvf-jj6q/GHSA-77vg-gpvf-jj6q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77vg-gpvf-jj6q", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41903" + ], + "details": "A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41903" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-716317.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7cq6-gv65-j962/GHSA-7cq6-gv65-j962.json b/advisories/unreviewed/2024/08/GHSA-7cq6-gv65-j962/GHSA-7cq6-gv65-j962.json new file mode 100644 index 00000000000..bd235b1d131 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7cq6-gv65-j962/GHSA-7cq6-gv65-j962.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7cq6-gv65-j962", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41904" + ], + "details": "A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41904" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-716317.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7jf9-xqjc-725f/GHSA-7jf9-xqjc-725f.json b/advisories/unreviewed/2024/08/GHSA-7jf9-xqjc-725f/GHSA-7jf9-xqjc-725f.json new file mode 100644 index 00000000000..4bc95350ade --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7jf9-xqjc-725f/GHSA-7jf9-xqjc-725f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jf9-xqjc-725f", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41905" + ], + "details": "A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41905" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-716317.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json b/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json index 5407e42ac7b..4f1a3fb7f80 100644 --- a/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json +++ b/advisories/unreviewed/2024/08/GHSA-885x-f949-h663/GHSA-885x-f949-h663.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-885x-f949-h663", - "modified": "2024-08-02T12:31:43Z", + "modified": "2024-08-13T09:30:52Z", "published": "2024-08-02T12:31:43Z", "aliases": [ "CVE-2024-38876" diff --git a/advisories/unreviewed/2024/08/GHSA-8g9j-h3c4-q352/GHSA-8g9j-h3c4-q352.json b/advisories/unreviewed/2024/08/GHSA-8g9j-h3c4-q352/GHSA-8g9j-h3c4-q352.json new file mode 100644 index 00000000000..98ed0988da2 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8g9j-h3c4-q352/GHSA-8g9j-h3c4-q352.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g9j-h3c4-q352", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41939" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41939" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8pm7-8j9r-gr39/GHSA-8pm7-8j9r-gr39.json b/advisories/unreviewed/2024/08/GHSA-8pm7-8j9r-gr39/GHSA-8pm7-8j9r-gr39.json new file mode 100644 index 00000000000..893e21b04b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8pm7-8j9r-gr39/GHSA-8pm7-8j9r-gr39.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pm7-8j9r-gr39", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-39922" + ], + "details": "A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA1) (All versions), LOGO! 24CEo (6ED1052-2CC08-0BA1) (All versions), LOGO! 24RCE (6ED1052-1HB08-0BA1) (All versions), LOGO! 24RCEo (6ED1052-2HB08-0BA1) (All versions), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1) (All versions), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1) (All versions), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1) (All versions), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1) (All versions), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1) (All versions), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1) (All versions), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1) (All versions), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1) (All versions). Affected devices store user passwords in plaintext without proper protection. This could allow a physical attacker to retrieve them from the embedded storage ICs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39922" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-921449.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-8wvx-w97g-7fq3/GHSA-8wvx-w97g-7fq3.json b/advisories/unreviewed/2024/08/GHSA-8wvx-w97g-7fq3/GHSA-8wvx-w97g-7fq3.json new file mode 100644 index 00000000000..d69c89eb69c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-8wvx-w97g-7fq3/GHSA-8wvx-w97g-7fq3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wvx-w97g-7fq3", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41681" + ], + "details": "A vulnerability has been identified in Location Intelligence family (All versions < V4.4). The web server of affected products is configured to support weak ciphers by default. This could allow an unauthenticated attacker in an on-path position to to read and modify any data passed over the connection between legitimate clients and the affected device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41681" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-720392.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-96w9-8q2h-2vpm/GHSA-96w9-8q2h-2vpm.json b/advisories/unreviewed/2024/08/GHSA-96w9-8q2h-2vpm/GHSA-96w9-8q2h-2vpm.json new file mode 100644 index 00000000000..0f4e13961a8 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-96w9-8q2h-2vpm/GHSA-96w9-8q2h-2vpm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96w9-8q2h-2vpm", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41941" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and modify settings in the application without authorization.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41941" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9gq5-mwjf-5wf3/GHSA-9gq5-mwjf-5wf3.json b/advisories/unreviewed/2024/08/GHSA-9gq5-mwjf-5wf3/GHSA-9gq5-mwjf-5wf3.json new file mode 100644 index 00000000000..6b7d4d6de4b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9gq5-mwjf-5wf3/GHSA-9gq5-mwjf-5wf3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gq5-mwjf-5wf3", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-36398" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\\SYSTEM`. This could allow a local attacker to execute operating system commands with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36398" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9w3w-43cp-9hpg/GHSA-9w3w-43cp-9hpg.json b/advisories/unreviewed/2024/08/GHSA-9w3w-43cp-9hpg/GHSA-9w3w-43cp-9hpg.json new file mode 100644 index 00000000000..bd47b46f50e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9w3w-43cp-9hpg/GHSA-9w3w-43cp-9hpg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w3w-43cp-9hpg", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41978" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices insert sensitive information about the generation of 2FA tokens into log files. This could allow an authenticated remote attacker to forge 2FA tokens of other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41978" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-087301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-f957-w8wh-r29f/GHSA-f957-w8wh-r29f.json b/advisories/unreviewed/2024/08/GHSA-f957-w8wh-r29f/GHSA-f957-w8wh-r29f.json new file mode 100644 index 00000000000..a318d08341c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-f957-w8wh-r29f/GHSA-f957-w8wh-r29f.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f957-w8wh-r29f", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41906" + ], + "details": "A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41906" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-716317.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-524" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jm3q-4p3v-cv8w/GHSA-jm3q-4p3v-cv8w.json b/advisories/unreviewed/2024/08/GHSA-jm3q-4p3v-cv8w/GHSA-jm3q-4p3v-cv8w.json new file mode 100644 index 00000000000..19cf89aaf3e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jm3q-4p3v-cv8w/GHSA-jm3q-4p3v-cv8w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm3q-4p3v-cv8w", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41907" + ], + "details": "A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41907" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-716317.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-358" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jv74-c838-vcpf/GHSA-jv74-c838-vcpf.json b/advisories/unreviewed/2024/08/GHSA-jv74-c838-vcpf/GHSA-jv74-c838-vcpf.json new file mode 100644 index 00000000000..2a949b8163d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jv74-c838-vcpf/GHSA-jv74-c838-vcpf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv74-c838-vcpf", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41938" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web application contains a path traversal vulnerability. This could allow an authenticated attacker it to delete arbitrary certificate files on the drive SINEC NMS is installed on.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41938" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-m3qr-mjwp-7555/GHSA-m3qr-mjwp-7555.json b/advisories/unreviewed/2024/08/GHSA-m3qr-mjwp-7555/GHSA-m3qr-mjwp-7555.json new file mode 100644 index 00000000000..2c5a9598141 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m3qr-mjwp-7555/GHSA-m3qr-mjwp-7555.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3qr-mjwp-7555", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41940" + ], + "details": "A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41940" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pv6j-85rr-wr2m/GHSA-pv6j-85rr-wr2m.json b/advisories/unreviewed/2024/08/GHSA-pv6j-85rr-wr2m/GHSA-pv6j-85rr-wr2m.json new file mode 100644 index 00000000000..c25ad641ab5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-pv6j-85rr-wr2m/GHSA-pv6j-85rr-wr2m.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv6j-85rr-wr2m", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41908" + ], + "details": "A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41908" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-357412.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-q664-pc24-53jx/GHSA-q664-pc24-53jx.json b/advisories/unreviewed/2024/08/GHSA-q664-pc24-53jx/GHSA-q664-pc24-53jx.json new file mode 100644 index 00000000000..a938be6b8db --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-q664-pc24-53jx/GHSA-q664-pc24-53jx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q664-pc24-53jx", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41976" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices do not properly validate input in specific VPN configuration fields. This could allow an authenticated remote attacker to execute arbitrary code on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41976" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-087301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vxg9-7hhf-p3mh/GHSA-vxg9-7hhf-p3mh.json b/advisories/unreviewed/2024/08/GHSA-vxg9-7hhf-p3mh/GHSA-vxg9-7hhf-p3mh.json new file mode 100644 index 00000000000..44f2d615655 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vxg9-7hhf-p3mh/GHSA-vxg9-7hhf-p3mh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxg9-7hhf-p3mh", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41977" + ], + "details": "A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.1), SCALANCE M812-1 ADSL-Router family (All versions < V8.1), SCALANCE M816-1 ADSL-Router family (All versions < V8.1), SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2) (All versions < V8.1), SCALANCE M874-2 (6GK5874-2AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 (6GK5874-3AA00-2AA2) (All versions < V8.1), SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2) (All versions < V8.1), SCALANCE M876-3 (6GK5876-3AA02-2BA2) (All versions < V8.1), SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2) (All versions < V8.1), SCALANCE M876-4 (6GK5876-4AA10-2BA2) (All versions < V8.1), SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2) (All versions < V8.1), SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2) (All versions < V8.1), SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1) (All versions < V8.1), SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1) (All versions < V8.1), SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1) (All versions < V8.1), SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1) (All versions < V8.1), SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1) (All versions < V8.1), SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1) (All versions < V8.1), SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1) (All versions < V8.1), SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1) (All versions < V8.1), SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2) (All versions < V8.1), SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2) (All versions < V8.1). Affected devices do not properly enforce isolation between user sessions in their web server component. This could allow an authenticated remote attacker to escalate their privileges on the devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41977" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-087301.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-488" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w2hf-r35h-cf3q/GHSA-w2hf-r35h-cf3q.json b/advisories/unreviewed/2024/08/GHSA-w2hf-r35h-cf3q/GHSA-w2hf-r35h-cf3q.json new file mode 100644 index 00000000000..c448b17d895 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w2hf-r35h-cf3q/GHSA-w2hf-r35h-cf3q.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2hf-r35h-cf3q", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-7715" + ], + "details": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240812. It has been classified as critical. This affects the function sprintf of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument filter leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7715" + }, + { + "type": "WEB", + "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_photo_search.md" + }, + { + "type": "WEB", + "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.274281" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.274281" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.389261" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w4fw-p9x9-hwxh/GHSA-w4fw-p9x9-hwxh.json b/advisories/unreviewed/2024/08/GHSA-w4fw-p9x9-hwxh/GHSA-w4fw-p9x9-hwxh.json new file mode 100644 index 00000000000..b2bd798ff39 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w4fw-p9x9-hwxh/GHSA-w4fw-p9x9-hwxh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4fw-p9x9-hwxh", + "modified": "2024-08-13T09:30:52Z", + "published": "2024-08-13T09:30:52Z", + "aliases": [ + "CVE-2024-41683" + ], + "details": "A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41683" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-720392.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T08:15:12Z" + } +} \ No newline at end of file