Machinesense
Machinesense Feverwarn Firmware: vulnerabilidades y CVE
Machinesense Feverwarn Firmware tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6221 | Media (6.5) | 0.58% | — | 1 feb 2024 | The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently… |
| CVE-2023-49617 | Crítica (9.1) | 0.80% | — | 1 feb 2024 | The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication. |
| CVE-2023-49610 | Alta (8.1) | 0.39% | — | 1 feb 2024 | MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack. |
| CVE-2023-49115 | Alta (7.5) | 0.59% | — | 1 feb 2024 | MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users. |
| CVE-2023-47867 | Alta (8.8) | 0.40% | — | 1 feb 2024 | MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device. |
| CVE-2023-46706 | Crítica (9.8) | 0.65% | — | 1 feb 2024 | Multiple MachineSense devices have credentials unable to be changed by the user or administrator. |