« Volver al listado

Enelx

Enelx Waybox PRO Firmware: vulnerabilidades y CVE

Enelx Waybox PRO Firmware tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-29126Alta (8.8)0.26%—5 nov 2024
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
CVE-2023-29125Alta (8)0.30%—5 nov 2024
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
CVE-2023-29121Alta (8.8)0.28%—5 nov 2024
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
CVE-2023-29120Alta (8.8)0.34%—5 nov 2024
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
CVE-2023-29119Alta (8.8)0.34%—5 nov 2024
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.
CVE-2023-29118Alta (8.8)0.34%—5 nov 2024
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.
CVE-2023-29117Alta (8.8)0.32%—5 nov 2024
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
CVE-2023-29116Media (4.3)0.23%—5 nov 2024
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.
CVE-2023-29115Media (6.5)0.28%—5 nov 2024
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services7
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter2
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Enelx