diff --git a/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json b/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json index 5ad846850b9..80164c7c27f 100644 --- a/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json +++ b/advisories/unreviewed/2022/05/GHSA-52mm-w3hf-39rg/GHSA-52mm-w3hf-39rg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-52mm-w3hf-39rg", - "modified": "2022-05-05T00:29:10Z", + "modified": "2024-03-28T03:30:57Z", "published": "2022-05-05T00:29:10Z", "aliases": [ "CVE-2013-4184" ], "details": "Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -34,6 +37,18 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/86103" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3F2KOK2SM2LFI4BNFOVV2G2XVJQBIMZL" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DTKH3TWUOXBAAZST7364UVZ4UPH4CEO7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MATNG5VP46SXJB2JHAI2LXPUXCYUOYPE" + }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2013-4184" @@ -49,7 +64,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-59" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json index 1f76395992d..9538997744f 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json +++ b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cj9-wjmr-5w57", - "modified": "2024-03-11T15:31:24Z", + "modified": "2024-03-28T03:30:58Z", "published": "2024-03-11T15:31:24Z", "aliases": [ "CVE-2024-1441" @@ -28,6 +28,14 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2263841" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/45FFKU3LODT345LAB5T4XZA5WKYMXJYU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6MVZO5GXDB7RHY6MS3ZXES3HPK34P3A" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-35p2-8gmg-pp6j/GHSA-35p2-8gmg-pp6j.json b/advisories/unreviewed/2024/03/GHSA-35p2-8gmg-pp6j/GHSA-35p2-8gmg-pp6j.json new file mode 100644 index 00000000000..c9254c6ef4e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-35p2-8gmg-pp6j/GHSA-35p2-8gmg-pp6j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p2-8gmg-pp6j", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:58Z", + "aliases": [ + "CVE-2024-28007" + ], + "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28007" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-47wm-wmj9-988c/GHSA-47wm-wmj9-988c.json b/advisories/unreviewed/2024/03/GHSA-47wm-wmj9-988c/GHSA-47wm-wmj9-988c.json new file mode 100644 index 00000000000..84e801e2770 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-47wm-wmj9-988c/GHSA-47wm-wmj9-988c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47wm-wmj9-988c", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28015" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28015" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json b/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json new file mode 100644 index 00000000000..0fd6f44541a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-4fwq-rwj5-pm2v/GHSA-4fwq-rwj5-pm2v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fwq-rwj5-pm2v", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28012" + ], + "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28012" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5577-w73m-r8xv/GHSA-5577-w73m-r8xv.json b/advisories/unreviewed/2024/03/GHSA-5577-w73m-r8xv/GHSA-5577-w73m-r8xv.json new file mode 100644 index 00000000000..1d544f3304e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5577-w73m-r8xv/GHSA-5577-w73m-r8xv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5577-w73m-r8xv", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28008" + ], + "details": "Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28008" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-489" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-f8m7-cqq6-85jp/GHSA-f8m7-cqq6-85jp.json b/advisories/unreviewed/2024/03/GHSA-f8m7-cqq6-85jp/GHSA-f8m7-cqq6-85jp.json new file mode 100644 index 00000000000..065768651f4 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-f8m7-cqq6-85jp/GHSA-f8m7-cqq6-85jp.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8m7-cqq6-85jp", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-3014" + ], + "details": "A vulnerability classified as critical has been found in SourceCodester Simple Subscription Website 1.0. Affected is an unknown function of the file Actions.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258300.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3014" + }, + { + "type": "WEB", + "url": "https://github.com/Viciglu/cvehub/blob/main/Simple%20Subscription%20Website%20with%20Admin%20System%20Actions.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.305648" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json b/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json new file mode 100644 index 00000000000..ce55432b46e --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fqmj-j6qq-43c5/GHSA-fqmj-j6qq-43c5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqmj-j6qq-43c5", + "modified": "2024-03-28T03:30:58Z", + "published": "2024-03-28T03:30:58Z", + "aliases": [ + "CVE-2024-28005" + ], + "details": "Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker who has obtained high privileges can execute arbitrary scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28005" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json b/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json new file mode 100644 index 00000000000..832816702ee --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2v-wvxg-x978", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-2111" + ], + "details": "The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2111" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3054883%40events-manager&new=3054883%40events-manager&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/95ded4bf-9964-4bb3-b6e5-5ad37360f87d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json b/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json new file mode 100644 index 00000000000..b8eb3d1ab92 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-g5x6-qxv4-vxw3/GHSA-g5x6-qxv4-vxw3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5x6-qxv4-vxw3", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28013" + ], + "details": "Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to change settings via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28013" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-330" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-m86q-2rv9-qf8h/GHSA-m86q-2rv9-qf8h.json b/advisories/unreviewed/2024/03/GHSA-m86q-2rv9-qf8h/GHSA-m86q-2rv9-qf8h.json new file mode 100644 index 00000000000..ad1276389ff --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-m86q-2rv9-qf8h/GHSA-m86q-2rv9-qf8h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m86q-2rv9-qf8h", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28009" + ], + "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28009" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-mgm7-v27r-x559/GHSA-mgm7-v27r-x559.json b/advisories/unreviewed/2024/03/GHSA-mgm7-v27r-x559/GHSA-mgm7-v27r-x559.json new file mode 100644 index 00000000000..55ae6d2169a --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-mgm7-v27r-x559/GHSA-mgm7-v27r-x559.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgm7-v27r-x559", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-3013" + ], + "details": "A vulnerability was found in FLIR AX8 up to 1.46.16. It has been rated as critical. This issue affects some unknown processing of the file /tools/test_login.php?action=register of the component User Registration. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258299. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3013" + }, + { + "type": "WEB", + "url": "https://h0e4a0r1t.github.io/2024/vulns/FLIR-AX8%20Fixed%20Thermal%20Cameras%20Register%20any%20user%20in%20the%20background--test_login.php.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258299" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258299" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.301588" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json b/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json new file mode 100644 index 00000000000..8a6519392b2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcgx-35gv-6fvj", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-2110" + ], + "details": "The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking statuses via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2110" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3054883/events-manager/trunk/classes/em-bookings-table.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0538999-0a09-4d24-a530-a32fb5b4e5e6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json b/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json new file mode 100644 index 00000000000..89c9fa1ef4f --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pfj3-88wv-9pg5/GHSA-pfj3-88wv-9pg5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfj3-88wv-9pg5", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-2091" + ], + "details": "The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.13.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2091" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/tags/1.13/modules/comparison-table/widgets/comparison-table.php#L2076" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3055134%40addon-elements-for-elementor-page-builder&new=3055134%40addon-elements-for-elementor-page-builder&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/18e2e0e5-495f-4f55-b7d8-94193fc2ad12?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json b/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json new file mode 100644 index 00000000000..b3131e74e76 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-phrr-qc3r-4v9p/GHSA-phrr-qc3r-4v9p.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phrr-qc3r-4v9p", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-3024" + ], + "details": "A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-258333 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3024" + }, + { + "type": "WEB", + "url": "https://docs.google.com/document/d/1wCIrViAJwGsO5afPBLLjRhO5RClsoUo3J9q1psLs84s/edit?usp=sharing" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1zV9MSkfYLIrdtK3yczy1qbsJr_yN2fwH/view" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258333" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258333" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.297866" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T02:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pxvf-gqv8-f2qh/GHSA-pxvf-gqv8-f2qh.json b/advisories/unreviewed/2024/03/GHSA-pxvf-gqv8-f2qh/GHSA-pxvf-gqv8-f2qh.json new file mode 100644 index 00000000000..d47d256c07c --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-pxvf-gqv8-f2qh/GHSA-pxvf-gqv8-f2qh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxvf-gqv8-f2qh", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-1770" + ], + "details": "The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.2 via deserialization of untrusted input in the get_post_data function. This makes it possible for authenticated attackers, with contributor access or higher, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1770" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3054910/meta-tag-manager/trunk/meta-tag-manager.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ec1aed2-d299-4fa9-add6-10b63ed6aa30?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T02:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json b/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json new file mode 100644 index 00000000000..107e4c29839 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q43x-m6x8-fxgx/GHSA-q43x-m6x8-fxgx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q43x-m6x8-fxgx", + "modified": "2024-03-28T03:30:58Z", + "published": "2024-03-28T03:30:58Z", + "aliases": [ + "CVE-2024-28006" + ], + "details": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to view device information.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28006" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q8c2-5pg9-qp4h/GHSA-q8c2-5pg9-qp4h.json b/advisories/unreviewed/2024/03/GHSA-q8c2-5pg9-qp4h/GHSA-q8c2-5pg9-qp4h.json new file mode 100644 index 00000000000..c5bbdc7b5be --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q8c2-5pg9-qp4h/GHSA-q8c2-5pg9-qp4h.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8c2-5pg9-qp4h", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28016" + ], + "details": "Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to get device informations via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28016" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qhhg-8h2m-8332/GHSA-qhhg-8h2m-8332.json b/advisories/unreviewed/2024/03/GHSA-qhhg-8h2m-8332/GHSA-qhhg-8h2m-8332.json new file mode 100644 index 00000000000..43b53dc7215 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qhhg-8h2m-8332/GHSA-qhhg-8h2m-8332.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhhg-8h2m-8332", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-3015" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Simple Subscription Website 1.0. Affected by this vulnerability is an unknown functionality of the file manage_plan.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258301 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3015" + }, + { + "type": "WEB", + "url": "https://github.com/Viciglu/cvehub/blob/main/Simple%20Subscription%20Website%20with%20Admin%20System%20manage_plan.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.258301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.258301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.305649" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T02:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json b/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json new file mode 100644 index 00000000000..a5205c36356 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-rrmx-g79h-w4q7/GHSA-rrmx-g79h-w4q7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmx-g79h-w4q7", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28010" + ], + "details": "Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28010" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json b/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json new file mode 100644 index 00000000000..8bd3662613b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v6qj-65jf-4qvc/GHSA-v6qj-65jf-4qvc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6qj-65jf-4qvc", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28014" + ], + "details": "Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary command via the internet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28014" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json b/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json new file mode 100644 index 00000000000..662349ada45 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-wrf8-rqf2-f8rc/GHSA-wrf8-rqf2-f8rc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrf8-rqf2-f8rc", + "modified": "2024-03-28T03:30:59Z", + "published": "2024-03-28T03:30:59Z", + "aliases": [ + "CVE-2024-28011" + ], + "details": "Hidden Functionality vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN and MR02LN all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28011" + }, + { + "type": "WEB", + "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-912" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-28T01:15:47Z" + } +} \ No newline at end of file