« Volver al listado

Helmholz

Helmholz REX 100 Firmware: vulnerabilidades y CVE

Helmholz REX 100 Firmware tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-45276Alta (7.5)0.63%—15 oct 2024
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
CVE-2024-45275Crítica (9.8)0.80%—15 oct 2024
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
CVE-2024-45274Crítica (9.8)1.5%—15 oct 2024
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-45273Alta (7.8)0.09%—15 oct 2024
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
CVE-2024-45271Alta (7.8)0.31%—15 oct 2024
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1059 Command and Scripting Interpreter2
  3. T1068 Exploitation for Privilege Escalation2
  4. T1005 Data from Local System1
  5. T1078.001 Default Accounts1
  6. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Helmholz