From 9c73f0eba45623b64c9e450ac555c9c20121ee4c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Sep 2024 09:32:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5v6g-vfrc-9w8p.json | 6 +- .../GHSA-xq7r-x85c-27jm.json | 6 +- .../GHSA-245x-752w-r292.json | 58 +++++++++++++++++++ .../GHSA-4gj3-5752-q8g8.json | 39 +++++++++++++ .../GHSA-5hm7-x82q-99rh.json | 50 ++++++++++++++++ .../GHSA-6fx3-92c8-8qcg.json | 38 ++++++++++++ .../GHSA-7294-67g5-cc6w.json | 38 ++++++++++++ .../GHSA-c4g6-rrx2-j7rm.json | 38 ++++++++++++ .../GHSA-chpx-369q-wwrx.json | 38 ++++++++++++ .../GHSA-cv2j-h5xr-4xvm.json | 38 ++++++++++++ .../GHSA-fqgj-hf47-9p78.json | 38 ++++++++++++ .../GHSA-g5w2-fv74-7p86.json | 38 ++++++++++++ .../GHSA-hmhp-m2mf-h8m9.json | 38 ++++++++++++ .../GHSA-hq46-f53r-2cxj.json | 38 ++++++++++++ .../GHSA-jh49-frp2-9886.json | 38 ++++++++++++ .../GHSA-jx9q-9xj3-cp3g.json | 38 ++++++++++++ .../GHSA-mpv2-j6xc-wcp7.json | 38 ++++++++++++ .../GHSA-pg7h-4x9w-92w3.json | 38 ++++++++++++ .../GHSA-r53h-jp5f-7qxm.json | 38 ++++++++++++ .../GHSA-r743-pq9r-5jgm.json | 38 ++++++++++++ .../GHSA-rcj3-r74w-96hp.json | 58 +++++++++++++++++++ .../GHSA-rhjq-jm8v-8g8r.json | 38 ++++++++++++ .../GHSA-vq98-jh26-q3x7.json | 38 ++++++++++++ .../GHSA-vw69-gxfr-pfgr.json | 38 ++++++++++++ .../GHSA-wh7r-mh88-6fj5.json | 38 ++++++++++++ .../GHSA-wxh2-rq3c-2j2g.json | 38 ++++++++++++ .../GHSA-x32q-36fr-233c.json | 38 ++++++++++++ 27 files changed, 1013 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json create mode 100644 advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json create mode 100644 advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json create mode 100644 advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json create mode 100644 advisories/unreviewed/2024/09/GHSA-7294-67g5-cc6w/GHSA-7294-67g5-cc6w.json create mode 100644 advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json create mode 100644 advisories/unreviewed/2024/09/GHSA-cv2j-h5xr-4xvm/GHSA-cv2j-h5xr-4xvm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json create mode 100644 advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json create mode 100644 advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jh49-frp2-9886/GHSA-jh49-frp2-9886.json create mode 100644 advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-r743-pq9r-5jgm/GHSA-r743-pq9r-5jgm.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json create mode 100644 advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json create mode 100644 advisories/unreviewed/2024/09/GHSA-vw69-gxfr-pfgr/GHSA-vw69-gxfr-pfgr.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json create mode 100644 advisories/unreviewed/2024/09/GHSA-wxh2-rq3c-2j2g/GHSA-wxh2-rq3c-2j2g.json create mode 100644 advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json diff --git a/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json b/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json index b70f4393689..ac144535e45 100644 --- a/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json +++ b/advisories/unreviewed/2024/06/GHSA-5v6g-vfrc-9w8p/GHSA-5v6g-vfrc-9w8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v6g-vfrc-9w8p", - "modified": "2024-08-19T21:35:07Z", + "modified": "2024-09-10T09:31:11Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-39463" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/fe17ebf22feb4ad7094d597526d558a49aac92b4" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1194" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json b/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json index 4706d00aadc..491b4f28ad2 100644 --- a/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json +++ b/advisories/unreviewed/2024/08/GHSA-xq7r-x85c-27jm/GHSA-xq7r-x85c-27jm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq7r-x85c-27jm", - "modified": "2024-09-03T15:30:40Z", + "modified": "2024-09-10T09:31:11Z", "published": "2024-08-30T09:31:17Z", "aliases": [ "CVE-2024-44944" @@ -52,6 +52,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/eb4ca1a97e08ff5b920664ba292e576257e2d184" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-1182" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json b/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json new file mode 100644 index 00000000000..5330ea91477 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-245x-752w-r292/GHSA-245x-752w-r292.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-245x-752w-r292", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-7618" + ], + "details": "The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7618" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/peepso-core/tags/6.4.4.0/templates/reactions/admin_reaction.php#L112" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/peepso-core/tags/6.4.6.0/classes/adminconfigreactions.php?rev=3147528#L88" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3147528" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/peepso-core/#developers" + }, + { + "type": "WEB", + "url": "https://www.peepso.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/edf2e060-5ae4-4b46-bc68-22ae5f516fe8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json new file mode 100644 index 00000000000..252bfa9a5a2 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-4gj3-5752-q8g8/GHSA-4gj3-5752-q8g8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gj3-5752-q8g8", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-44072" + ], + "details": "OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44072" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN12824024" + }, + { + "type": "WEB", + "url": "https://www.buffalo.jp/news/detail/20240719-01.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T07:15:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json b/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json new file mode 100644 index 00000000000..3ed21aae894 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-5hm7-x82q-99rh/GHSA-5hm7-x82q-99rh.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hm7-x82q-99rh", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-8258" + ], + "details": "Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49314" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50643" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8258" + }, + { + "type": "WEB", + "url": "https://github.com/r3ggi/electroniz3r" + }, + { + "type": "WEB", + "url": "https://www.electronjs.org/docs/latest/tutorial/fuses" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json b/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json new file mode 100644 index 00000000000..95b2d4d56f3 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-6fx3-92c8-8qcg/GHSA-6fx3-92c8-8qcg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fx3-92c8-8qcg", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-42424" + ], + "details": "Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42424" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000227014/dsa-2024-327" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-7294-67g5-cc6w/GHSA-7294-67g5-cc6w.json b/advisories/unreviewed/2024/09/GHSA-7294-67g5-cc6w/GHSA-7294-67g5-cc6w.json new file mode 100644 index 00000000000..e81f603230b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-7294-67g5-cc6w/GHSA-7294-67g5-cc6w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7294-67g5-cc6w", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-39581" + ], + "details": "Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39581" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228412/dsa-2024-360-security-update-for-dell-powerscale-insightiq-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json b/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json new file mode 100644 index 00000000000..c7fecf40c28 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-c4g6-rrx2-j7rm/GHSA-c4g6-rrx2-j7rm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4g6-rrx2-j7rm", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43392" + ], + "details": "A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43392" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json b/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json new file mode 100644 index 00000000000..768d3ebc90a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-chpx-369q-wwrx/GHSA-chpx-369q-wwrx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chpx-369q-wwrx", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-7699" + ], + "details": "An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7699" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cv2j-h5xr-4xvm/GHSA-cv2j-h5xr-4xvm.json b/advisories/unreviewed/2024/09/GHSA-cv2j-h5xr-4xvm/GHSA-cv2j-h5xr-4xvm.json new file mode 100644 index 00000000000..ac390bea953 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cv2j-h5xr-4xvm/GHSA-cv2j-h5xr-4xvm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv2j-h5xr-4xvm", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43389" + ], + "details": "A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43389" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json b/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json new file mode 100644 index 00000000000..1d21b23a4ee --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fqgj-hf47-9p78/GHSA-fqgj-hf47-9p78.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqgj-hf47-9p78", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43391" + ], + "details": "A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43391" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json b/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json new file mode 100644 index 00000000000..50c87a8a0e1 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-g5w2-fv74-7p86/GHSA-g5w2-fv74-7p86.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5w2-fv74-7p86", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43388" + ], + "details": "A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43388" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json b/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json new file mode 100644 index 00000000000..a51aa912e03 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hmhp-m2mf-h8m9/GHSA-hmhp-m2mf-h8m9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmhp-m2mf-h8m9", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-6596" + ], + "details": "An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6596" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json b/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json new file mode 100644 index 00000000000..32d8692e5fc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-hq46-f53r-2cxj/GHSA-hq46-f53r-2cxj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq46-f53r-2cxj", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43386" + ], + "details": "A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43386" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jh49-frp2-9886/GHSA-jh49-frp2-9886.json b/advisories/unreviewed/2024/09/GHSA-jh49-frp2-9886/GHSA-jh49-frp2-9886.json new file mode 100644 index 00000000000..18a05e03afd --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jh49-frp2-9886/GHSA-jh49-frp2-9886.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh49-frp2-9886", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-39582" + ], + "details": "Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39582" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228412/dsa-2024-360-security-update-for-dell-powerscale-insightiq-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json b/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json new file mode 100644 index 00000000000..e089edc2ec4 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-jx9q-9xj3-cp3g/GHSA-jx9q-9xj3-cp3g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx9q-9xj3-cp3g", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-42425" + ], + "details": "Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42425" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000227015/dsa-2024-328" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-788" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json b/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json new file mode 100644 index 00000000000..a262156dc92 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-mpv2-j6xc-wcp7/GHSA-mpv2-j6xc-wcp7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mpv2-j6xc-wcp7", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-39580" + ], + "details": "Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39580" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228412/dsa-2024-360-security-update-for-dell-powerscale-insightiq-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json b/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json new file mode 100644 index 00000000000..db3ac4ccfcc --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-pg7h-4x9w-92w3/GHSA-pg7h-4x9w-92w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg7h-4x9w-92w3", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-42427" + ], + "details": "Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42427" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228350/dsa-2024-386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json b/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json new file mode 100644 index 00000000000..cc6a7a51842 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r53h-jp5f-7qxm/GHSA-r53h-jp5f-7qxm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r53h-jp5f-7qxm", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43385" + ], + "details": "A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43385" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-r743-pq9r-5jgm/GHSA-r743-pq9r-5jgm.json b/advisories/unreviewed/2024/09/GHSA-r743-pq9r-5jgm/GHSA-r743-pq9r-5jgm.json new file mode 100644 index 00000000000..a61b85187be --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-r743-pq9r-5jgm/GHSA-r743-pq9r-5jgm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r743-pq9r-5jgm", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43393" + ], + "details": "A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43393" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json b/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json new file mode 100644 index 00000000000..6156dc6ce31 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rcj3-r74w-96hp/GHSA-rcj3-r74w-96hp.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcj3-r74w-96hp", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-7655" + ], + "details": "The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7655" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/peepso-core/tags/6.4.6.0/classes/adminconfigfields.php?rev=3147528#L17" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3147528" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/peepso-core/#developers" + }, + { + "type": "WEB", + "url": "https://www.peepso.com/6-4-6-0" + }, + { + "type": "WEB", + "url": "https://www.peepso.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e85ee611-ae81-4736-b4f0-b9d06714da18?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json b/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json new file mode 100644 index 00000000000..38dceb5775d --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-rhjq-jm8v-8g8r/GHSA-rhjq-jm8v-8g8r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhjq-jm8v-8g8r", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-7734" + ], + "details": "An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7734" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T08:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json b/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json new file mode 100644 index 00000000000..41b6bd621fe --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vq98-jh26-q3x7/GHSA-vq98-jh26-q3x7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq98-jh26-q3x7", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-7698" + ], + "details": "A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7698" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-212" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vw69-gxfr-pfgr/GHSA-vw69-gxfr-pfgr.json b/advisories/unreviewed/2024/09/GHSA-vw69-gxfr-pfgr/GHSA-vw69-gxfr-pfgr.json new file mode 100644 index 00000000000..812b8830e11 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vw69-gxfr-pfgr/GHSA-vw69-gxfr-pfgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw69-gxfr-pfgr", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43390" + ], + "details": "A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43390" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json b/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json new file mode 100644 index 00000000000..053c64ba2d5 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wh7r-mh88-6fj5/GHSA-wh7r-mh88-6fj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh7r-mh88-6fj5", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-43387" + ], + "details": "A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43387" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-wxh2-rq3c-2j2g/GHSA-wxh2-rq3c-2j2g.json b/advisories/unreviewed/2024/09/GHSA-wxh2-rq3c-2j2g/GHSA-wxh2-rq3c-2j2g.json new file mode 100644 index 00000000000..ee473c434a6 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-wxh2-rq3c-2j2g/GHSA-wxh2-rq3c-2j2g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxh2-rq3c-2j2g", + "modified": "2024-09-10T09:31:11Z", + "published": "2024-09-10T09:31:11Z", + "aliases": [ + "CVE-2024-39574" + ], + "details": "Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39574" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228412/dsa-2024-360-security-update-for-dell-powerscale-insightiq-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json b/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json new file mode 100644 index 00000000000..f6d9c1275cf --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-x32q-36fr-233c/GHSA-x32q-36fr-233c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x32q-36fr-233c", + "modified": "2024-09-10T09:31:12Z", + "published": "2024-09-10T09:31:12Z", + "aliases": [ + "CVE-2024-39583" + ], + "details": "Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39583" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000228412/dsa-2024-360-security-update-for-dell-powerscale-insightiq-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-10T09:15:03Z" + } +} \ No newline at end of file