|
196611
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software
|
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s enc…
|
NVD-CWE-noinfo
|
CVE-2021-26360
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
5.5 |
MEDIUM
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_2200ge_firmware ryzen_3_2200g_firmware ryzen_5_2400ge_firmware…
|
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poi…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-26393
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_5300ge_firmware ryzen_3_5300g_firmware ryzen_5_5600ge_firmware…
|
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.
|
NVD-CWE-noinfo
|
CVE-2021-26391
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
7.5 |
HIGH
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) c…
|
NVD-CWE-Other
|
CVE-2021-26733
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
5.3 |
MEDIUM
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner I…
|
NVD-CWE-Other
|
CVE-2021-26732
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26731
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26730
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges …
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26729
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26728
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privilege…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26727
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|