|
196111
|
9.4 |
CRITICAL
Network
|
abb busch-jaeger
|
mybuildings mybusch-jaeger
|
The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.…
|
NVD-CWE-noinfo
|
CVE-2021-22272
|
2024-11-21 14:49 |
2021-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196112
|
5.5 |
MEDIUM
Local
|
abb
|
system_access_point_2.0_firmware system_access_point_127v_firmware wl-system_access_point_127v_firmware wl-system_access_point_firmware wl-system_access_point_2.0_firmware
|
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2021-22276
|
2024-11-21 14:49 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196113
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-3040_firmware
|
An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can conn…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-21913
|
2024-11-21 14:49 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196114
|
5.5 |
MEDIUM
Local
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter …
|
NVD-CWE-noinfo
|
CVE-2021-22020
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196115
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a s…
|
NVD-CWE-noinfo
|
CVE-2021-22019
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196116
|
6.5 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit t…
|
NVD-CWE-noinfo
|
CVE-2021-22018
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196117
|
5.3 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this …
|
NVD-CWE-noinfo
|
CVE-2021-22017
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196118
|
6.1 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim in…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22016
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196119
|
7.8 |
HIGH
Local
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-22015
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196120
|
7.2 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter…
|
NVD-CWE-noinfo
|
CVE-2021-22014
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|