Snapav
Snapav Wattbox Wb-300-ip-3 Firmware: vulnerabilidades y CVE
Snapav Wattbox Wb-300-ip-3 Firmware tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-23582 | Crítica (9.8) | 0.83% | — | 30 ene 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code or crash the device remotely. |
| CVE-2023-22389 | Media (6.5) | 0.48% | — | 30 ene 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the… |
| CVE-2023-24020 | Crítica (9.8) | 0.65% | — | 30 ene 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login. |
| CVE-2023-22315 | Alta (7.8) | 0.11% | — | 30 ene 2023 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does not verify updates to the device. An attacker could upload a malformed update file to the device… |