Sunbirddcim
Sunbirddcim Dctrack: vulnerabilidades y CVE
Sunbirddcim Dctrack tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-66238 | Alta (7.4) | 0.34% | — | 4 dic 2025 | DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appliance's virtual console could exploit these features to redirect network traffic, potentially… |
| CVE-2025-66237 | Alta (8.4) | 0.13% | — | 4 dic 2025 | DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the… |
| CVE-2024-37776 | Media (4.8) | 0.30% | — | 16 dic 2024 | A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens. |
| CVE-2024-37775 | Alta (7.5) | 0.47% | — | 16 dic 2024 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check. |
| CVE-2024-37774 | Alta (8) | 0.20% | — | 16 dic 2024 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. |
| CVE-2024-37773 | Media (4.8) | 0.23% | — | 16 dic 2024 | An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen. |