diff --git a/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json b/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json new file mode 100644 index 00000000000..c43a442bcc0 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-449w-g66x-h54j/GHSA-449w-g66x-h54j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-449w-g66x-h54j", + "modified": "2024-01-16T12:30:25Z", + "published": "2024-01-16T12:30:25Z", + "aliases": [ + "CVE-2023-52100" + ], + "details": "The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52100" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4895-cxh8-gwhw/GHSA-4895-cxh8-gwhw.json b/advisories/unreviewed/2024/01/GHSA-4895-cxh8-gwhw/GHSA-4895-cxh8-gwhw.json new file mode 100644 index 00000000000..5b30a13470b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4895-cxh8-gwhw/GHSA-4895-cxh8-gwhw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4895-cxh8-gwhw", + "modified": "2024-01-16T12:30:25Z", + "published": "2024-01-16T12:30:25Z", + "aliases": [ + "CVE-2023-52099" + ], + "details": "Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52099" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5m86-gj68-x34m/GHSA-5m86-gj68-x34m.json b/advisories/unreviewed/2024/01/GHSA-5m86-gj68-x34m/GHSA-5m86-gj68-x34m.json new file mode 100644 index 00000000000..153f4185305 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5m86-gj68-x34m/GHSA-5m86-gj68-x34m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5m86-gj68-x34m", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2024-0556" + ], + "details": "A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials in plain text.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0556" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-261" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6jf4-pg2m-9838/GHSA-6jf4-pg2m-9838.json b/advisories/unreviewed/2024/01/GHSA-6jf4-pg2m-9838/GHSA-6jf4-pg2m-9838.json new file mode 100644 index 00000000000..0b2bf3df0d6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6jf4-pg2m-9838/GHSA-6jf4-pg2m-9838.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jf4-pg2m-9838", + "modified": "2024-01-16T12:30:25Z", + "published": "2024-01-16T12:30:25Z", + "aliases": [ + "CVE-2023-52101" + ], + "details": "Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52101" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json b/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json new file mode 100644 index 00000000000..1cc71daadc4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6xr5-p6cj-8mrm/GHSA-6xr5-p6cj-8mrm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xr5-p6cj-8mrm", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2023-52104" + ], + "details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52104" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json b/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json new file mode 100644 index 00000000000..63b4a9934cb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-77jm-r76q-g5ph/GHSA-77jm-r76q-g5ph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77jm-r76q-g5ph", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2023-52106" + ], + "details": "The DownloadProviderMain module has a vulnerability in API permission verification. Successful exploitation of this vulnerability may affect integrity and availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52106" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fcww-v4hr-rgfr/GHSA-fcww-v4hr-rgfr.json b/advisories/unreviewed/2024/01/GHSA-fcww-v4hr-rgfr/GHSA-fcww-v4hr-rgfr.json new file mode 100644 index 00000000000..e58641306b1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fcww-v4hr-rgfr/GHSA-fcww-v4hr-rgfr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcww-v4hr-rgfr", + "modified": "2024-01-16T12:30:25Z", + "published": "2024-01-16T12:30:25Z", + "aliases": [ + "CVE-2023-34063" + ], + "details": "Aria Automation contains a Missing Access Control vulnerability.\n\n\nAn authenticated malicious actor may \nexploit this vulnerability leading to unauthorized access to remote \norganizations and workflows.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34063" + }, + { + "type": "WEB", + "url": "https://www.vmware.com/security/advisories/VMSA-2024-0001.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-g9rx-x2rh-fgcf/GHSA-g9rx-x2rh-fgcf.json b/advisories/unreviewed/2024/01/GHSA-g9rx-x2rh-fgcf/GHSA-g9rx-x2rh-fgcf.json new file mode 100644 index 00000000000..c7658861fd8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-g9rx-x2rh-fgcf/GHSA-g9rx-x2rh-fgcf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9rx-x2rh-fgcf", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2023-52103" + ], + "details": "Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52103" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p4ff-mmmp-q474/GHSA-p4ff-mmmp-q474.json b/advisories/unreviewed/2024/01/GHSA-p4ff-mmmp-q474/GHSA-p4ff-mmmp-q474.json new file mode 100644 index 00000000000..41b74d72ddd --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p4ff-mmmp-q474/GHSA-p4ff-mmmp-q474.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4ff-mmmp-q474", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2024-0554" + ], + "details": "A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device model parameter via '/setup/diags_ir_learn.asp', allowing the attacker to retrieve the session details of another user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0554" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json b/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json new file mode 100644 index 00000000000..078f13266b4 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-p53v-hm2g-p66x/GHSA-p53v-hm2g-p66x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p53v-hm2g-p66x", + "modified": "2024-01-16T12:30:25Z", + "published": "2024-01-16T12:30:25Z", + "aliases": [ + "CVE-2023-52102" + ], + "details": "Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52102" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vvp5-2ffm-gmvh/GHSA-vvp5-2ffm-gmvh.json b/advisories/unreviewed/2024/01/GHSA-vvp5-2ffm-gmvh/GHSA-vvp5-2ffm-gmvh.json new file mode 100644 index 00000000000..089912ffc90 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-vvp5-2ffm-gmvh/GHSA-vvp5-2ffm-gmvh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvp5-2ffm-gmvh", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2024-0555" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions inside the application they are logged in. This vulnerability is possible due to the lack of propper CSRF token implementation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0555" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-full-compass-systems-wic1200" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json new file mode 100644 index 00000000000..4b41b8d35ae --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x697-v25m-6phv/GHSA-x697-v25m-6phv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x697-v25m-6phv", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2024-0553" + ], + "details": "A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-0553 is designated as an incomplete resolution for CVE-2023-5981.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0553" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-0553" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258412" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gnutls/gnutls/-/issues/1522" + }, + { + "type": "WEB", + "url": "https://lists.gnupg.org/pipermail/gnutls-help/2024-January/004841.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T12:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json b/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json new file mode 100644 index 00000000000..810acc00d71 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xr5r-3m93-q3f2/GHSA-xr5r-3m93-q3f2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr5r-3m93-q3f2", + "modified": "2024-01-16T12:30:26Z", + "published": "2024-01-16T12:30:26Z", + "aliases": [ + "CVE-2023-52105" + ], + "details": "The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52105" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/1/" + }, + { + "type": "WEB", + "url": "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202401-0000001799925977" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-16T10:15:07Z" + } +} \ No newline at end of file