Publish Advisories

GHSA-449w-g66x-h54j
GHSA-4895-cxh8-gwhw
GHSA-5m86-gj68-x34m
GHSA-6jf4-pg2m-9838
GHSA-6xr5-p6cj-8mrm
GHSA-77jm-r76q-g5ph
GHSA-fcww-v4hr-rgfr
GHSA-g9rx-x2rh-fgcf
GHSA-p4ff-mmmp-q474
GHSA-p53v-hm2g-p66x
GHSA-vvp5-2ffm-gmvh
GHSA-x697-v25m-6phv
GHSA-xr5r-3m93-q3f2
This commit is contained in:
advisory-database[bot]
2024-01-16 12:32:00 +00:00
parent 6c52e37c32
commit f93a4787b9
13 changed files with 514 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-449w-g66x-h54j",
"modified": "2024-01-16T12:30:25Z",
"published": "2024-01-16T12:30:25Z",
"aliases": [
"CVE-2023-52100"
],
"details": "The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52100"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4895-cxh8-gwhw",
"modified": "2024-01-16T12:30:25Z",
"published": "2024-01-16T12:30:25Z",
"aliases": [
"CVE-2023-52099"
],
"details": "Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52099"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5m86-gj68-x34m",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0556"
],
"details": "A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials in plain text.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0556"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
}
],
"database_specific": {
"cwe_ids": [
"CWE-261"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T11:15:08Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6jf4-pg2m-9838",
"modified": "2024-01-16T12:30:25Z",
"published": "2024-01-16T12:30:25Z",
"aliases": [
"CVE-2023-52101"
],
"details": "Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52101"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6xr5-p6cj-8mrm",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2023-52104"
],
"details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52104"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77jm-r76q-g5ph",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2023-52106"
],
"details": "The DownloadProviderMain module has a vulnerability in API permission verification. Successful exploitation of this vulnerability may affect integrity and availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52106"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fcww-v4hr-rgfr",
"modified": "2024-01-16T12:30:25Z",
"published": "2024-01-16T12:30:25Z",
"aliases": [
"CVE-2023-34063"
],
"details": "Aria Automation contains a Missing Access Control vulnerability.\n\n\nAn authenticated malicious actor may \nexploit this vulnerability leading to unauthorized access to remote \norganizations and workflows.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34063"
},
{
"type": "WEB",
"url": "https://www.vmware.com/security/advisories/VMSA-2024-0001.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9rx-x2rh-fgcf",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2023-52103"
],
"details": "Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52103"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4ff-mmmp-q474",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0554"
],
"details": "A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device model parameter via '/setup/diags_ir_learn.asp', allowing the attacker to retrieve the session details of another user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0554"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T11:15:07Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p53v-hm2g-p66x",
"modified": "2024-01-16T12:30:25Z",
"published": "2024-01-16T12:30:25Z",
"aliases": [
"CVE-2023-52102"
],
"details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52102"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvp5-2ffm-gmvh",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0555"
],
"details": "A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions inside the application they are logged in. This vulnerability is possible due to the lack of propper CSRF token implementation.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0555"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T11:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x697-v25m-6phv",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0553"
],
"details": "A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0553"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0553"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258412"
},
{
"type": "WEB",
"url": "https://gitlab.com/gnutls/gnutls/-/issues/1522"
},
{
"type": "WEB",
"url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-203"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T12:15:45Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xr5r-3m93-q3f2",
"modified": "2024-01-16T12:30:26Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2023-52105"
],
"details": "The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52105"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2024/1/"
},
{
"type": "WEB",
"url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-16T10:15:07Z"
}
}