Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.41%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all…
ModificadaCrítica (9.8)2.0%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's…
ModificadaAlta (8.8)1.8%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is…
ModificadaMedia (6.1)0.82%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to…