Auto-Update: 2024-10-28T09:00:19.199014+00:00

This commit is contained in:
cad-safe-bot 2024-10-28 09:03:21 +00:00
parent 8688904c75
commit 804a3b5810
6 changed files with 78 additions and 39 deletions

View File

@ -2,13 +2,13 @@
"id": "CVE-2023-39982",
"sourceIdentifier": "psirt@moxa.com",
"published": "2023-09-02T13:15:45.347",
"lastModified": "2023-09-08T13:23:36.153",
"vulnStatus": "Analyzed",
"lastModified": "2024-10-28T07:15:07.037",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.\n\n"
"value": "A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic."
},
{
"lang": "es",
@ -76,7 +76,7 @@
"description": [
{
"lang": "en",
"value": "CWE-798"
"value": "CWE-321"
}
]
}

View File

@ -2,13 +2,13 @@
"id": "CVE-2023-5962",
"sourceIdentifier": "psirt@moxa.com",
"published": "2023-12-23T09:15:08.050",
"lastModified": "2024-01-03T20:04:06.947",
"vulnStatus": "Analyzed",
"lastModified": "2024-10-28T07:15:07.333",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization.\n\n"
"value": "A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization."
},
{
"lang": "es",
@ -76,7 +76,7 @@
"description": [
{
"lang": "en",
"value": "CWE-327"
"value": "CWE-328"
}
]
}

View File

@ -2,13 +2,13 @@
"id": "CVE-2024-0387",
"sourceIdentifier": "psirt@moxa.com",
"published": "2024-02-26T16:27:49.890",
"lastModified": "2024-02-26T16:32:25.577",
"lastModified": "2024-10-28T07:15:07.497",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.\n\n"
"value": "The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests."
},
{
"lang": "es",
@ -46,7 +46,7 @@
"description": [
{
"lang": "en",
"value": "CWE-441"
"value": "CWE-1188"
}
]
}

View File

@ -0,0 +1,44 @@
{
"id": "CVE-2024-38821",
"sourceIdentifier": "security@vmware.com",
"published": "2024-10-28T07:15:07.633",
"lastModified": "2024-10-28T07:15:07.633",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances.\n\nFor this to impact an application, all of the following must be true:\n\n * It must be a WebFlux application\n * It must be using Spring's static resources support\n * It must have a non-permitAll authorization rule applied to the static resources support"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security@vmware.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"references": [
{
"url": "https://spring.io/security/cve-2024-38821",
"source": "security@vmware.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-10-28T07:00:19.420329+00:00
2024-10-28T09:00:19.199014+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-10-28T06:15:04.593000+00:00
2024-10-28T07:15:07.633000+00:00
```
### Last Data Feed Release
@ -33,29 +33,23 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
267217
267218
```
### CVEs added in the last Commit
Recently added CVEs: `2`
Recently added CVEs: `1`
- [CVE-2024-50307](CVE-2024/CVE-2024-503xx/CVE-2024-50307.json) (`2024-10-28T05:15:03.203`)
- [CVE-2024-9162](CVE-2024/CVE-2024-91xx/CVE-2024-9162.json) (`2024-10-28T06:15:04.593`)
- [CVE-2024-38821](CVE-2024/CVE-2024-388xx/CVE-2024-38821.json) (`2024-10-28T07:15:07.633`)
### CVEs modified in the last Commit
Recently modified CVEs: `8`
Recently modified CVEs: `3`
- [CVE-2023-33237](CVE-2023/CVE-2023-332xx/CVE-2023-33237.json) (`2024-10-28T06:15:02.730`)
- [CVE-2023-33238](CVE-2023/CVE-2023-332xx/CVE-2023-33238.json) (`2024-10-28T06:15:03.147`)
- [CVE-2023-33239](CVE-2023/CVE-2023-332xx/CVE-2023-33239.json) (`2024-10-28T06:15:03.393`)
- [CVE-2023-34213](CVE-2023/CVE-2023-342xx/CVE-2023-34213.json) (`2024-10-28T06:15:03.600`)
- [CVE-2023-34214](CVE-2023/CVE-2023-342xx/CVE-2023-34214.json) (`2024-10-28T06:15:03.760`)
- [CVE-2023-34215](CVE-2023/CVE-2023-342xx/CVE-2023-34215.json) (`2024-10-28T06:15:03.950`)
- [CVE-2023-39981](CVE-2023/CVE-2023-399xx/CVE-2023-39981.json) (`2024-10-28T06:15:04.167`)
- [CVE-2023-4227](CVE-2023/CVE-2023-42xx/CVE-2023-4227.json) (`2024-10-28T06:15:04.370`)
- [CVE-2023-39982](CVE-2023/CVE-2023-399xx/CVE-2023-39982.json) (`2024-10-28T07:15:07.037`)
- [CVE-2023-5962](CVE-2023/CVE-2023-59xx/CVE-2023-5962.json) (`2024-10-28T07:15:07.333`)
- [CVE-2024-0387](CVE-2024/CVE-2024-03xx/CVE-2024-0387.json) (`2024-10-28T07:15:07.497`)
## Download and Usage

View File

@ -225387,9 +225387,9 @@ CVE-2023-33231,0,0,09f86d8066d74c7874dbea9cc2ad06aac59a2df7122675bfda30672a291d4
CVE-2023-33234,0,0,8c3bc362e58c079b32d4a0791724c2c1cfa09349b40fca7b2ef6d10dc4db9437,2024-10-10T15:35:07.983000
CVE-2023-33235,0,0,98d0a7eb19704063a78a382792254db430678a754513fb8bc0821026290e2114,2023-05-30T19:43:02.460000
CVE-2023-33236,0,0,4f9a68681c8de805fc0155196f19f195d6dec29aeda4ac774c34b5b3dd85bcb0,2023-05-30T19:29:08.573000
CVE-2023-33237,0,1,d786704a126da7c25ba580deb1701358e3b2e2a97b7eacf43df307f3c8d43a24,2024-10-28T06:15:02.730000
CVE-2023-33238,0,1,e23f1bd98d7f7e5ed0fb1e667344afe549002ede49ee7114f14bd22ddf6369e5,2024-10-28T06:15:03.147000
CVE-2023-33239,0,1,509f9663663694c30e325890088cd2291bc09ad0eb3bc26b11c60837fab56fea,2024-10-28T06:15:03.393000
CVE-2023-33237,0,0,d786704a126da7c25ba580deb1701358e3b2e2a97b7eacf43df307f3c8d43a24,2024-10-28T06:15:02.730000
CVE-2023-33238,0,0,e23f1bd98d7f7e5ed0fb1e667344afe549002ede49ee7114f14bd22ddf6369e5,2024-10-28T06:15:03.147000
CVE-2023-33239,0,0,509f9663663694c30e325890088cd2291bc09ad0eb3bc26b11c60837fab56fea,2024-10-28T06:15:03.393000
CVE-2023-3324,0,0,6b73b02d2dac3432e473dc11300a3534848b4c72ba438443dab98ee4d47ef851,2023-08-01T21:12:32.530000
CVE-2023-33240,0,0,045a1b0a2646c41b9b86cb06420a7554d3e32e7c478fbfc3c818013263afca28,2023-05-26T03:32:54.867000
CVE-2023-33241,0,0,36b269910f3c9c1e26ec0bc965386c08195bb4a131ae6a62cb3423dec09a53fd,2023-08-25T16:14:33.433000
@ -226111,9 +226111,9 @@ CVE-2023-3421,0,0,417c7c373f8932aa81f54dff446323d7be5801a93d8782975947f7650e841a
CVE-2023-34210,0,0,eeee0fa065c1a4e8cbe56d44018dbc5b0a10e616aa699f86019997c86a0ee8e1,2023-10-20T18:10:16.097000
CVE-2023-34211,0,0,2a2a5ee7504f70b72e2cd36df650acbffcc887587d63620323b0a832ed326a6c,2023-11-07T04:15:32.030000
CVE-2023-34212,0,0,715c0da3e46bba861d1484d269db8395d9649d4eb955ec87d30054559a16f619,2023-06-21T15:18:21.630000
CVE-2023-34213,0,1,20f7f931529ef727e7d5ed1d42e7e2515a23e174f9b2aef22b1c248451a87681,2024-10-28T06:15:03.600000
CVE-2023-34214,0,1,33bd3d106bb4347c4cfd2deb7619243b31842c80f6dc7c994608d09a95fc1ad8,2024-10-28T06:15:03.760000
CVE-2023-34215,0,1,9b3ef8552f1949951f63537780f8a1032e1f05b11b8850d7f888124885babcac,2024-10-28T06:15:03.950000
CVE-2023-34213,0,0,20f7f931529ef727e7d5ed1d42e7e2515a23e174f9b2aef22b1c248451a87681,2024-10-28T06:15:03.600000
CVE-2023-34214,0,0,33bd3d106bb4347c4cfd2deb7619243b31842c80f6dc7c994608d09a95fc1ad8,2024-10-28T06:15:03.760000
CVE-2023-34215,0,0,9b3ef8552f1949951f63537780f8a1032e1f05b11b8850d7f888124885babcac,2024-10-28T06:15:03.950000
CVE-2023-34216,0,0,04143175a518bdc966e71697d423aa3c36a68752a5ed7f27337e8bf2e7b2de15,2023-08-23T15:08:57.020000
CVE-2023-34217,0,0,6540d2b8e3c6c22014690c6f01d3e5e3f1c60d4a6482d20e1adf6ce4450b54d7,2023-08-23T16:41:43.143000
CVE-2023-34218,0,0,a9d7a0cfbb6bf18280940bed045aba8fda347fa1ce99ee0bff3d76c33785b9d9,2023-06-06T20:02:39.667000
@ -230355,8 +230355,8 @@ CVE-2023-39978,0,0,6a57c413fca429aa0b904c11231329cb75471b6bdf3919c3fb4662ce94920
CVE-2023-39979,0,0,28ba0e888954da30fd1114720a4d4ec97a7abc002585512616eb63d2f2e943b4,2023-09-07T20:16:28.350000
CVE-2023-3998,0,0,1f43d7ee043779eb60cd321b7ac366db37948e4caeb09b7d4bfe80c2001f4f53,2023-11-07T04:20:06.317000
CVE-2023-39980,0,0,dc0997ef40d03680f823152a64bb0472a38a140bfa52cf5b05dff64b94503ab7,2023-09-07T20:29:10.830000
CVE-2023-39981,0,1,42ff74f872e17f113d20bc5fb66bb21db4a56462c34eee11fb347b4d4c23b12d,2024-10-28T06:15:04.167000
CVE-2023-39982,0,0,a75711da5dea31a3f2bb1f5e3f7ad3190c7297abb86acc601851b03379c4c260,2023-09-08T13:23:36.153000
CVE-2023-39981,0,0,42ff74f872e17f113d20bc5fb66bb21db4a56462c34eee11fb347b4d4c23b12d,2024-10-28T06:15:04.167000
CVE-2023-39982,0,1,aa9400efcbd9643672097960b7b37a033a4ab2e8f729843de691cf5f32b3d3bd,2024-10-28T07:15:07.037000
CVE-2023-39983,0,0,e03990be69dfc1acd00d2500a11f172019b4a412cee0b915d28071580822e25d,2023-09-08T14:22:27.980000
CVE-2023-39984,0,0,9d662b11d581fc3abb1f1d8a77fed29b0424ab98a622e0ca8931efb2871fb556,2024-09-27T02:15:09.777000
CVE-2023-39985,0,0,a976827f365efe4831a5eaefdaca4d2ed40eb3f28ef0b1a60cfd926ff4343cdd,2024-08-02T19:15:35.070000
@ -232151,7 +232151,7 @@ CVE-2023-42253,0,0,ddc0ec667c1a768417786714deb5cbd25861a4a1519c75ff38636e887b869
CVE-2023-4226,0,0,505e49d9f96a99b76056cf6143d350619626a79924b032cb4fc6b5070876540d,2023-11-30T05:34:06.420000
CVE-2023-42261,0,0,ee0b962b4658d438acb083a2e057d2bd12f4a7a5c718ad7d73fe4169295bf0fd,2024-08-02T20:15:22.350000
CVE-2023-42268,0,0,10c990470b2c8e37165632758ea54865ff15431c80a09a197502127ff6a705ee,2023-09-12T19:24:30.050000
CVE-2023-4227,0,1,89f0ffe537dad0662f1e6172b0b52367161bbc1f13b5d4fb284d1de2b91c8e49,2024-10-28T06:15:04.370000
CVE-2023-4227,0,0,89f0ffe537dad0662f1e6172b0b52367161bbc1f13b5d4fb284d1de2b91c8e49,2024-10-28T06:15:04.370000
CVE-2023-42270,0,0,6e55386a1608989e07c7a0163c6d3f0e92bb9c9576b1d8ab571f5b606ef526e1,2024-02-02T17:15:10.793000
CVE-2023-42276,0,0,c9c2e6d3b0979901fa51e9964c0d2dda78aedc2948212e936e72edafaed63e10,2023-09-13T00:35:56.567000
CVE-2023-42277,0,0,23f6694014a4ba84370488d128c7e22c34f27bb61d711b5ff8e85b61b84137b9,2023-09-13T00:32:07.417000
@ -240277,7 +240277,7 @@ CVE-2023-5958,0,0,bba32800deeb7d30a99f3712c89f98653957f3494e7c4f1e8515c1476f9c7e
CVE-2023-5959,0,0,2a3ce7cc3890313dc12b3709f7087b005aa8f79913f3cee0fbf9f8cfb635d389,2024-05-17T02:33:26.003000
CVE-2023-5960,0,0,7c243403becdbbe3850cb2c9d98362f70223c838d815897a932034335e29076c,2023-12-01T21:43:59.323000
CVE-2023-5961,0,0,49a2a752b83fdacde4a269003dc0089cd2d6fb8a9b7325337a35e1c64f04f19e,2023-12-28T15:26:49.127000
CVE-2023-5962,0,0,3d2ce324f8a119a3d7c98bd9fe95509264d2a1a2fd9aee3e53cc3940e2ebfa65,2024-01-03T20:04:06.947000
CVE-2023-5962,0,1,60234f47cd5ff20c4401cac288d29c03a5475530cb8438e55b02dc7f15c770e2,2024-10-28T07:15:07.333000
CVE-2023-5963,0,0,69644472c24c0d35562164160447c6a4622e8ff3b7ee162913edd003b69574f9,2024-10-03T07:15:24.720000
CVE-2023-5964,0,0,d2cc6a2e1fcdf8fe568dd2c4dd1022dbf63a321878e41417f3a318bb8a15a619,2023-11-21T18:15:09.550000
CVE-2023-5965,0,0,73e1c2d163ccfbdba2f0a99cb65c09b3884f89006282e3f2f21dabad18123dce,2023-12-06T17:21:03.737000
@ -241771,7 +241771,7 @@ CVE-2024-0383,0,0,85bac9fa293ab75d877bc41c8ef81c5579319ee2c32c4c6f5f5ac00d65bd1a
CVE-2024-0384,0,0,a4add3eabdee058f057ce7429d512cb284387958ed63e5f544e44c699f706553,2024-02-07T23:32:14.717000
CVE-2024-0385,0,0,ff24cecc3aa0829465f7c435ab1d28dc310e953ac0cfad9c189f97d9cad9290f,2024-03-13T18:16:18.563000
CVE-2024-0386,0,0,eb09787265717d3c33304b7e8e2b3332850f56654d176796526f9154957fc9aa,2024-03-13T12:33:51.697000
CVE-2024-0387,0,0,7819dad9baeaa185f244401811fa228597f72ad1e5f19b8274122afb4e71b023,2024-02-26T16:32:25.577000
CVE-2024-0387,0,1,ab2ace6e33a6270ff2561c6aa77a0af094466dfe572695ebf689c8147f66ec76,2024-10-28T07:15:07.497000
CVE-2024-0389,0,0,d1d24d35b0e19e39f84b15798565e0cc2f2d9e1cb7aa37c78307fe23d65c9c38,2024-05-17T02:34:34.973000
CVE-2024-0390,0,0,0b185184b3a31634ccb64d7354df5f92adbf30abedcf74871e60691c405574a0,2024-02-15T14:28:31.380000
CVE-2024-0393,0,0,12dd170d2fc156ebb8fbf17ffdb29e3ee860d25577cf7ee28b77ed0f15e7a39f,2024-01-12T06:15:47.157000
@ -257247,6 +257247,7 @@ CVE-2024-38817,0,0,09723b24db0d6a084c268e07b58c10ca202cbe9290f0f8fec2db45f626cd7
CVE-2024-38818,0,0,622849f8ff4dfc75febef96b69e498222845497635b94ea6c1bb47520700e61d,2024-10-10T12:51:56.987000
CVE-2024-3882,0,0,8cf286ca42c3a62eccb821d9ac0678dabad594eee248c127390ddaf169987d46,2024-05-17T02:40:10.457000
CVE-2024-38820,0,0,a5b616e0d9bc58c5d9f58ca8cd3d5a01be45dc2cf2e2573532c8a51afcf4ca4c,2024-10-22T15:42:22.633000
CVE-2024-38821,1,1,ce879ae3aee6155f7e2f4f9e1bfe057d72dd721016928130d54bea034c384e18,2024-10-28T07:15:07.633000
CVE-2024-3883,0,0,e6bda202b9fd54c10f25f29dd8ae0cebb83b1538aee636944c2fd66bf4045fff,2024-05-02T13:27:25.103000
CVE-2024-3885,0,0,9b28a2ee85edfe77753e71858fb1438bd68a9b6ee299843f3a5752cca4753d01,2024-05-02T18:00:37.360000
CVE-2024-38856,0,0,cf2c30abb1c3c3e6b03acfa253b7bd98efa464ab76b49fddc2034ce3ce8a3be1,2024-08-28T16:15:58.043000
@ -263496,7 +263497,7 @@ CVE-2024-5023,0,0,63ebd4218020d01998ceddb622d35154b9496df68f9db12eb6b4711fe09e7d
CVE-2024-5024,0,0,9dd3417f324a3df55f488e05c68d1854a15dd73bd49fdda06475c54e037a76e5,2024-09-04T14:33:57.200000
CVE-2024-5025,0,0,5975a4de967bb092ff1a32c8663c734972c139617eb709a92a7c0cc78b284359,2024-05-22T12:46:53.887000
CVE-2024-5028,0,0,6e4747168a055d3478d0389157f1378a0e5efd7245fc9814fa65e0cf7f805db7,2024-08-01T13:59:38.360000
CVE-2024-50307,1,1,97c3c548388a7bdbb1e7fef32d811a287b7adf85e781a4eb64e2c5a6e3d3da49,2024-10-28T05:15:03.203000
CVE-2024-50307,0,0,97c3c548388a7bdbb1e7fef32d811a287b7adf85e781a4eb64e2c5a6e3d3da49,2024-10-28T05:15:03.203000
CVE-2024-5031,0,0,5b0fce1eabb88a37a871d927606cb4ca5166c3808ddca60f777848c692bab12e,2024-05-22T12:46:53.887000
CVE-2024-50311,0,0,2a5a791ea9a6ed953dd59786f3feebf3d6f42a9a801f740efbdba1fdb4b4c644,2024-10-23T15:12:34.673000
CVE-2024-50312,0,0,e1c46649456e4db99a8bc5fe6e245d8f0cb367071dbc5cb51f03a7f5cb1f8348,2024-10-23T15:12:34.673000
@ -266771,7 +266772,7 @@ CVE-2024-9156,0,0,a219412140ed669efa4745f4f28cc6c7900dfc19ec3ad1e09069c0d323d2ba
CVE-2024-9158,0,0,4fc7d51e8c01309b5be37e99b987b450b97283230cd81ff5464aaed45b24a100,2024-10-07T16:13:49.027000
CVE-2024-9160,0,0,dcb08097a2707d90887b21cc5ab80eb6cf86ff84abb571a9a69f82310c298b71,2024-09-30T12:45:57.823000
CVE-2024-9161,0,0,b475702d9da1cd18a82129e88647b71b0425c30925f01e0c024257c76be8d651,2024-10-07T17:48:28.117000
CVE-2024-9162,1,1,fb4d55a666ac6f68fb059c5d9e29459f2a7c9ce73430c76a9e244f0a8dbfc808,2024-10-28T06:15:04.593000
CVE-2024-9162,0,0,fb4d55a666ac6f68fb059c5d9e29459f2a7c9ce73430c76a9e244f0a8dbfc808,2024-10-28T06:15:04.593000
CVE-2024-9164,0,0,22a852044a02fa2bf2a1f004c8f4e0e1dbd359605b1a68593f6ac0ec4a57bdec,2024-10-15T12:58:51.050000
CVE-2024-9166,0,0,b24f9ebc4650fb7d123f858805d8b1a753ef6a732064f8b14cd979bccf2c240a,2024-09-30T12:46:20.237000
CVE-2024-9167,0,0,c76cdd3c3965eaf83c5e43b4dbbb850b39e5a19995695c4b4450dc70c8263305,2024-10-10T12:56:30.817000

Can't render this file because it is too large.