Auto-Update: 2024-09-15T12:00:17.522193+00:00

This commit is contained in:
cad-safe-bot 2024-09-15 12:03:16 +00:00
parent 5381e159e6
commit c97730879f
4 changed files with 164 additions and 39 deletions

View File

@ -2,13 +2,13 @@
"id": "CVE-2024-28799",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2024-08-14T16:15:11.220",
"lastModified": "2024-09-11T13:43:16.067",
"vulnStatus": "Analyzed",
"lastModified": "2024-09-15T11:15:12.100",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173."
"value": "IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local user during back-end commands which may result in the unexpected disclosure of this information under certain conditions. IBM X-Force ID: 287173."
},
{
"lang": "es",

View File

@ -0,0 +1,137 @@
{
"id": "CVE-2024-8869",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-09-15T11:15:13.323",
"lastModified": "2024-09-15T11:15:13.323",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "LOW",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "LOW",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirements": "NOT_DEFINED",
"integrityRequirements": "NOT_DEFINED",
"availabilityRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnerableSystemConfidentiality": "NOT_DEFINED",
"modifiedVulnerableSystemIntegrity": "NOT_DEFINED",
"modifiedVulnerableSystemAvailability": "NOT_DEFINED",
"modifiedSubsequentSystemConfidentiality": "NOT_DEFINED",
"modifiedSubsequentSystemIntegrity": "NOT_DEFINED",
"modifiedSubsequentSystemAvailability": "NOT_DEFINED",
"safety": "NOT_DEFINED",
"automatable": "NOT_DEFINED",
"recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"baseScore": 2.3,
"baseSeverity": "LOW"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 5.0,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.6,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:H/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "HIGH",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.6
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/?ctiid.277506",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.277506",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.403211",
"source": "cna@vuldb.com"
},
{
"url": "https://www.totolink.net/",
"source": "cna@vuldb.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-09-15T10:00:17.644444+00:00
2024-09-15T12:00:17.522193+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-09-15T09:15:04.613000+00:00
2024-09-15T11:15:13.323000+00:00
```
### Last Data Feed Release
@ -33,34 +33,21 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
262901
262902
```
### CVEs added in the last Commit
Recently added CVEs: `15`
Recently added CVEs: `1`
- [CVE-2024-44053](CVE-2024/CVE-2024-440xx/CVE-2024-44053.json) (`2024-09-15T09:15:02.013`)
- [CVE-2024-44054](CVE-2024/CVE-2024-440xx/CVE-2024-44054.json) (`2024-09-15T09:15:02.290`)
- [CVE-2024-44056](CVE-2024/CVE-2024-440xx/CVE-2024-44056.json) (`2024-09-15T09:15:02.800`)
- [CVE-2024-44057](CVE-2024/CVE-2024-440xx/CVE-2024-44057.json) (`2024-09-15T09:15:03.270`)
- [CVE-2024-44058](CVE-2024/CVE-2024-440xx/CVE-2024-44058.json) (`2024-09-15T09:15:03.883`)
- [CVE-2024-44059](CVE-2024/CVE-2024-440xx/CVE-2024-44059.json) (`2024-09-15T09:15:04.613`)
- [CVE-2024-44060](CVE-2024/CVE-2024-440xx/CVE-2024-44060.json) (`2024-09-15T08:15:11.367`)
- [CVE-2024-44062](CVE-2024/CVE-2024-440xx/CVE-2024-44062.json) (`2024-09-15T08:15:12.710`)
- [CVE-2024-44063](CVE-2024/CVE-2024-440xx/CVE-2024-44063.json) (`2024-09-15T08:15:12.940`)
- [CVE-2024-45455](CVE-2024/CVE-2024-454xx/CVE-2024-45455.json) (`2024-09-15T08:15:13.150`)
- [CVE-2024-45456](CVE-2024/CVE-2024-454xx/CVE-2024-45456.json) (`2024-09-15T08:15:13.350`)
- [CVE-2024-45457](CVE-2024/CVE-2024-454xx/CVE-2024-45457.json) (`2024-09-15T08:15:13.547`)
- [CVE-2024-45458](CVE-2024/CVE-2024-454xx/CVE-2024-45458.json) (`2024-09-15T08:15:13.763`)
- [CVE-2024-45459](CVE-2024/CVE-2024-454xx/CVE-2024-45459.json) (`2024-09-15T08:15:13.963`)
- [CVE-2024-45460](CVE-2024/CVE-2024-454xx/CVE-2024-45460.json) (`2024-09-15T08:15:14.173`)
- [CVE-2024-8869](CVE-2024/CVE-2024-88xx/CVE-2024-8869.json) (`2024-09-15T11:15:13.323`)
### CVEs modified in the last Commit
Recently modified CVEs: `0`
Recently modified CVEs: `1`
- [CVE-2024-28799](CVE-2024/CVE-2024-287xx/CVE-2024-28799.json) (`2024-09-15T11:15:12.100`)
## Download and Usage

View File

@ -249137,7 +249137,7 @@ CVE-2024-28795,0,0,f736e56121f9e7ebf2951b32e296586930b34c2b92901741a56f804684721
CVE-2024-28796,0,0,9309b95ff28ad61ded45c96b0ce61eb28e84237793000fa8c06bf713a7309924,2024-07-18T12:28:43.707000
CVE-2024-28797,0,0,215c6e5211c115cb8a1dd99529c7ef7d500087d4643915a223453edd582d1174,2024-07-31T18:57:00.313000
CVE-2024-28798,0,0,a6356458c4f4311bbbb434bcb07b82d4a8232904c746806c3a615b0a524813c1,2024-07-31T19:33:56.337000
CVE-2024-28799,0,0,09ed4dc299411653eeeece6881b3b9b5c84e6b9f93868f4d5de80628d62fd7d7,2024-09-11T13:43:16.067000
CVE-2024-28799,0,1,36781abb27cfb24d367f0586559a4c30be05c5758b22ce701324d1887d1daa0d,2024-09-15T11:15:12.100000
CVE-2024-2880,0,0,c617aabe27a476530f11dd1aff9d0e70b8bc9314c3647a1cac79a81958f4d9d1,2024-07-12T16:55:30.137000
CVE-2024-28804,0,0,f7e3d6c3e14215e831a96b931ea15f5f72cb16cc7bfabd09d8b34530beca586f,2024-08-01T13:49:18.607000
CVE-2024-28805,0,0,57ffe0c5396b469d1d6aea3771a149218b95fafbad9b52c6f522fc5113787118,2024-08-01T13:49:19.450000
@ -259110,16 +259110,16 @@ CVE-2024-4401,0,0,48f8e641129f81284635fb93c6fe88c5c5fc547b585fa75e650b46a3bc3c0b
CVE-2024-4403,0,0,07b387e13ed3d47c920433d5f499100d4d5e53ffefe1712d98753a4da5408fe2,2024-06-10T18:06:22.600000
CVE-2024-4404,0,0,3ae3ea086edb9bd484931090d5df4b9ee138a4bfd155faf3c535f115da6a15de,2024-06-17T12:42:04.623000
CVE-2024-4405,0,0,45cc63f187ac8ca241b3f6f4ea8115546cfb9789c95e5b84e970d2850f40bb92,2024-05-02T18:00:37.360000
CVE-2024-44053,1,1,5e074093c8a83d5b8131bc3d4f2079a0f8e3b0989e822366d3e11964243746e7,2024-09-15T09:15:02.013000
CVE-2024-44054,1,1,5b33cacdf53e2936c71fb462e9af31b57726285303037a6f5e1c3ebffe1f54c2,2024-09-15T09:15:02.290000
CVE-2024-44056,1,1,36802a51a1f141563f7ae2ec10595be0015cdd15e5bba88bceddaf65752682ba,2024-09-15T09:15:02.800000
CVE-2024-44057,1,1,857b861e7d299092a8eee5852b3c381c958661ccc50f472ae205e3d0045f6273,2024-09-15T09:15:03.270000
CVE-2024-44058,1,1,431ed220de913710e4f04a7c10d35ccbeceaf08dbac3a3de71029ec7f9f9f3d5,2024-09-15T09:15:03.883000
CVE-2024-44059,1,1,71f7db7650b1dc6a337bbf53f26c4bad6ea712583035cade612aa7600468f790,2024-09-15T09:15:04.613000
CVE-2024-44053,0,0,5e074093c8a83d5b8131bc3d4f2079a0f8e3b0989e822366d3e11964243746e7,2024-09-15T09:15:02.013000
CVE-2024-44054,0,0,5b33cacdf53e2936c71fb462e9af31b57726285303037a6f5e1c3ebffe1f54c2,2024-09-15T09:15:02.290000
CVE-2024-44056,0,0,36802a51a1f141563f7ae2ec10595be0015cdd15e5bba88bceddaf65752682ba,2024-09-15T09:15:02.800000
CVE-2024-44057,0,0,857b861e7d299092a8eee5852b3c381c958661ccc50f472ae205e3d0045f6273,2024-09-15T09:15:03.270000
CVE-2024-44058,0,0,431ed220de913710e4f04a7c10d35ccbeceaf08dbac3a3de71029ec7f9f9f3d5,2024-09-15T09:15:03.883000
CVE-2024-44059,0,0,71f7db7650b1dc6a337bbf53f26c4bad6ea712583035cade612aa7600468f790,2024-09-15T09:15:04.613000
CVE-2024-4406,0,0,4d2edf89174eefb11c1e35948c69459d7b4d6dd1a09c10eb7a0704c1561ef984,2024-05-02T18:00:37.360000
CVE-2024-44060,1,1,7b8ed16da225ee3029be54091c9ae12a145fad43d62c91fa6f35db279aa36327,2024-09-15T08:15:11.367000
CVE-2024-44062,1,1,1644938a0273933f0faedd2cf5d72e06b6802cec154810df682c483da3d0df3c,2024-09-15T08:15:12.710000
CVE-2024-44063,1,1,345a218a7ef7a40ba13b180d84bc880cce7e5c93decfb3e39bbb7c8786febf07,2024-09-15T08:15:12.940000
CVE-2024-44060,0,0,7b8ed16da225ee3029be54091c9ae12a145fad43d62c91fa6f35db279aa36327,2024-09-15T08:15:11.367000
CVE-2024-44062,0,0,1644938a0273933f0faedd2cf5d72e06b6802cec154810df682c483da3d0df3c,2024-09-15T08:15:12.710000
CVE-2024-44063,0,0,345a218a7ef7a40ba13b180d84bc880cce7e5c93decfb3e39bbb7c8786febf07,2024-09-15T08:15:12.940000
CVE-2024-44067,0,0,f6acc392be4d580c3750239c741db14e9e0b23cb38f1820ef772266e93e1673a,2024-08-20T20:35:34.497000
CVE-2024-44069,0,0,2eb956dd06d71bb925b0fe816cbe078cd7c5c9a8647e07e8d081256cc543fa9f,2024-08-19T12:59:59.177000
CVE-2024-44070,0,0,897c04ba9a67e5ea511bddee651919522720d2ac02cb9c6411d8cfecd25984e1,2024-08-30T16:19:49.587000
@ -259629,13 +259629,13 @@ CVE-2024-45448,0,0,baaac6177753b9ef1526bea7e39de3dc043a4ca1913a07543e6e5e11685c2
CVE-2024-45449,0,0,16fcc8f3add1fcba18b36fc04f0c4a19c97d176cb514abd9722e7bafd45dc227,2024-09-06T14:38:08.067000
CVE-2024-4545,0,0,864a22773c6eaa7a20fdb4cf4c4b7a2709a2c8e64cfe98132d05364d67e97af4,2024-05-14T16:11:39.510000
CVE-2024-45450,0,0,aa5d1afac94647878136a29faab537df333625d6375aa0ea38189e29e05bb108,2024-09-12T19:30:22.863000
CVE-2024-45455,1,1,b4cf4fde6876b53f4e7fab33b129eab1ab20c61d4bbe2f8cdba2416abce11d35,2024-09-15T08:15:13.150000
CVE-2024-45456,1,1,081c1a09c229ea27d066d82a17ffbfa6a4152d86ca7e79f1bf4c1f8f6c724fce,2024-09-15T08:15:13.350000
CVE-2024-45457,1,1,ca78a7432951c5dc247ffc0d181692d008e90d64444293988a110264323b267f,2024-09-15T08:15:13.547000
CVE-2024-45458,1,1,6d88def5c36012ecdf6b48989da8064b23c7d4b35513c96f45ebc7124752eb2c,2024-09-15T08:15:13.763000
CVE-2024-45459,1,1,ca234fa487f89818483abf850b9dabb20e2d2562a2007dcbb1b042aafb9ffa04,2024-09-15T08:15:13.963000
CVE-2024-45455,0,0,b4cf4fde6876b53f4e7fab33b129eab1ab20c61d4bbe2f8cdba2416abce11d35,2024-09-15T08:15:13.150000
CVE-2024-45456,0,0,081c1a09c229ea27d066d82a17ffbfa6a4152d86ca7e79f1bf4c1f8f6c724fce,2024-09-15T08:15:13.350000
CVE-2024-45457,0,0,ca78a7432951c5dc247ffc0d181692d008e90d64444293988a110264323b267f,2024-09-15T08:15:13.547000
CVE-2024-45458,0,0,6d88def5c36012ecdf6b48989da8064b23c7d4b35513c96f45ebc7124752eb2c,2024-09-15T08:15:13.763000
CVE-2024-45459,0,0,ca234fa487f89818483abf850b9dabb20e2d2562a2007dcbb1b042aafb9ffa04,2024-09-15T08:15:13.963000
CVE-2024-4546,0,0,da973c82a9042d639d29e7a0c2ffb48d440dea200e6df21027887041c43a68db,2024-05-16T13:03:05.353000
CVE-2024-45460,1,1,87156fe69c7ba5be2401d5a4a8dca1dc6bd17b02e5e00b518fd9dc1bd705e762,2024-09-15T08:15:14.173000
CVE-2024-45460,0,0,87156fe69c7ba5be2401d5a4a8dca1dc6bd17b02e5e00b518fd9dc1bd705e762,2024-09-15T08:15:14.173000
CVE-2024-4547,0,0,e03413ba2a3d643e986abd6a70d4989a4412faae98e55cc280c4859673ba647d,2024-05-06T16:00:59.253000
CVE-2024-4548,0,0,c312b0154ade9cb7e93b29cf6468875ea09abcdae811bc20c1f6b28cb1f08ef2,2024-05-06T16:00:59.253000
CVE-2024-45488,0,0,02812af338aadc4a80122f84f222d800d57fc191e3e2ef216830d55dc271ef45,2024-08-30T19:35:06.870000
@ -262900,3 +262900,4 @@ CVE-2024-8865,0,0,a39e4f34a05995643d58a4005fb4dc7690ae0140dbe8fa6fe9528f952dddbf
CVE-2024-8866,0,0,31ba295c4f71cde54a98742cdc5d78078f4e8b948563abaa4e1dbb696b00e6f1,2024-09-15T02:15:01.900000
CVE-2024-8867,0,0,dd10831ef551fea3afb47529263b42e62dd84766cc54a4058c7ce2170e3f8ac1,2024-09-15T03:15:01.840000
CVE-2024-8868,0,0,4c0844b52c07af19f806d758bc94eea8b81aa10285bf079a34c6dd0100e86840,2024-09-15T03:15:02.153000
CVE-2024-8869,1,1,aa2af33ef0f85ca181820a682c28077f17b530186dae9e309043b826e1006c37,2024-09-15T11:15:13.323000

Can't render this file because it is too large.