CVE List - Iberia

  • Cybersecurity
  • Cybersecurity services
  • Spain
  • Type Cyber Threat Research
IDManufacturerDeviceFirmwareCVE IDCWEScoreCVSS Vector
1ZIV4CCT-EA6-334126BF3.23.80.27.36371CVE-2021-25909CWE-400: Uncontrolled Resource Consumption8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N 
/S:C/C:N/I:N/A:H
2ZIV4CCT-EA6-334126BF3.23.77.8.33251CVE-2021-25910CWE-287: Improper Authentication8CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ 
S:U/C:H/I:H/A:H
3CIRCUTORSGE-PLC10000.9.2bCVE-2021-33841CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)10CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ 
S:U/C:H/I:H/A:H
4CIRCUTORSGE-PLC10000.9.2bCVE-2021-33842CWE-565: Reliance on Cookies without Validation and Integrity Checking8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ 
S:U/C:H/I:H/A:
5CIRCUTORSGE-PLC10000.9.2bCVE-2011-0762
CVE-2011-2191
CVE-2012-0920
Several CVE10 
6SITELCAP/PRX5.2.01CVE-2021-32453CWE-306: Missing Authentication for Critical Function6.5CVSS:3.1/AV:A/AC:L/PR:L/UI:N/ 
S:U/C:L/I:L/A:H
7SITELCAP/PRX5.2.01CVE-2021-32455CWE-400: Uncontrolled Resource Consumption6.5CVSS:3.1/AV:A/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:H
8SITELCAP/PRX5.2.01CVE-2021-32454CWE-798: Use of Hard-coded Credentials9.6CVSS:3.1/AV:A/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
9ZIGORZIGOR TPS200 NG2.00CVE-2020-8973CWE-284: Improper Access Control9.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
10ZIGORZIGOR TPS200 NG2.00CVE-2020-8974CWE-434: Unrestricted upload of file with dangerious type10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
11ZIGORZIGOR TPS200 NG2.00CVE-2020-8975CWE-201: Exposure of Sensitive Information Through Sent Data7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
12ZIGORZIGOR TPS200 NG2.00CVE-2020-8976CWE-352: Cross-Site Request Forgery (CSRF)9.4CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
13SITELCAP/PRX5.2.01CVE-2021-32456CWE-319: Transmisión de información sensible en texto claro6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/
S:U/C:H/I:N/A:N
14ORMAZABALekorCCP601jCVE-2022-47553CWE-285: Improper Authorization8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
15ORMAZABALekorCCP601jCVE-2022-47554CWE-200: Exposure of Sensitive Information to an Unauthorized Actor8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:H/I:L/A:N
16ORMAZABALekorCCP601jCVE-2022-47555CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)9.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
17ORMAZABALekorCCP601jCVE-2022-47562CWE-770: Allocation of Resources Without Limits or Throttling7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
18ORMAZABALekorCCP601jCVE-2022-47556CWE-400: Uncontrolled Resource Consumption6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
19ORMAZABALekorCCP601jCVE-2022-47557CWE-916: Use of Password Hash With Insufficient Computational Effort6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:H/I:L/A:N
20ORMAZABALekorCCP601jCVE-2022-47558CWE-284: Improper Access Control9.4CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
21ORMAZABALekorCCP601jCVE-2022-47559CWE-352: Cross-Site Request Forgery (CSRF)8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
22ORMAZABALekorCCP601jCVE-2022-47560CWE-319: Cleartext Transmission of Sensitive Information5.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:H/I:L/A:N
23ORMAZABALekorCCP601jCVE-2022-47561CWE-256: Unprotected Storage of Credentials7.3CVSS:3.1/AV:L/AC:L/PR:N/UI:N/
S:U/C:H/I:L/A:L
24INGETEAMINGEPAC DALinux IngepacDA 
3.2.0-rt10_DA_1.0.0.21
#315 PREEMPT RT 
Wed Jul 15 13:17:29 CEST 2015 armv7l
CVE-2017-20007CWE-200: Exposure of Sensitive Information to an Unauthorized Actor5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:N/A:N
25DIGIDigi ConnectPort® X2D2.22.1CVE-2022-2634CWE-250: Execution with Unnecessary Privileges10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
26IPCOMMipDIO3.9 2016/04/18 / IPDIO_SW_3.9CVE-2022-24432CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:L/I:L/A:L
27IPCOMMipDIO3.9 2016/04/18 / IPDIO_SW_3.9CVE-2022-21146CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)6.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/
S:U/C:L/I:L/A:L
28IPCOMMipDIO3.9 2016/04/18 / IPDIO_SW_3.9CVE-2022-24915CWE-94: Improper Control of Generation of Code (‘Code Injection’)8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:H/I:H/A:H
29IPCOMMipDIO3.9 2016/04/18 / IPDIO_SW_3.9CVE-2022-22985CWE-94: Improper Control of Generation of Code (‘Code Injection’)8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/
S:U/C:H/I:H/A:H
30SIEMENSSpectrum Power™ 4Spectrum Power™ 4 (Spectrum Power 4.7 Service Pack 3)CVE-2022-23312CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/
S:U/C:L/I:L/A:N
31SIEMENSRSG908Cv5.5.4CVE-2022-34663CWE-94: Improper Control of Generation of Code (‘Code Injection’)8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:H/I:H/A:H
32INGETEAMINGEPAC DA34510.29.2.42CVE-2023-3768CWE-20: Improper input validation8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:N/I:N/A:H
33INGETEAM NGEPAC EF MDFC50660.22.6+6.1.1.22+5.3.1.1CVE-2023-3769CWE-20: Improper input validation8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:C/C:N/I:N/A:H
34INGETEAMINGEPAC DA34510.29.2.42CVE-2023-3770CWE-20: Improper input validation5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:N/A:N
35LANDISE580 Landis+Gyr ZMQ202E65CXE-2.2.0-build-20210503.160CVE-2022-3083CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax3.9CVSS:3.1/AV:L/AC:L/PR:L/UI:R/
S:C/C:N/I:L/A:L
36SAUTERSauter nova 200 – 2200 SeriesVersion 4.2.1.0 Dev.CVE-2023-0053CWE-319: Cleartext Transmission of Sensitive Information5.7CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:N/A:N
37SAUTERSauter nova 200 – 2200 SeriesVersion 4.2.1.0 Dev.CVE-2023-0052CWE-250: Execution with Unnecessary Privileges9.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/
S:U/C:H/I:H/A:H 
38SOCOMECMODULYS GP Green Power 2.0Netvision v7.20CVE-2023-0356CWE-261: Weak Encoding for Password7.5CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:N/A:N
39WESTERMOLynx 206-F2G4.24.1CVE-2023-40143CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:N
40WESTERMOLynx 206-F2G4.24.1CVE-2023-45222CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:N
41WESTERMOLynx 206-F2G4.24.1
CVE-2023-42765
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:N
42WESTERMOLynx 206-F2G4.24.1
1.17.2
CVE-2023-45227CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:N
43WESTERMOLynx 206-F2G4.24.1CVE-2023-40544CWE-319: Cleartext Transmission of Sensitive Information5.7CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:N/A:N
44WESTERMOLynx 206-F2G4.24.1CVE-2023-45213CWE-942: Permissive Cross-domain Policy with Untrusted Domains6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:C/C:H/I:N/A:N
45WESTERMOLynx 206-F2G4.24.1CVE-2023-45735CWE-94: Improper Control of Generation of Code (‘Code Injection’)8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:H/I:H/A:H
46WESTERMOLynx 206-F2G4.24.1CVE-2023-38579CWE-352: Cross-Site Request Forgery (CSRF)8CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:H/I:H/A:H
47LANTRONIXXportDevice Server Configuration Manager version 1.8.0.1CVE-2023-7237CWE-261: Weak Encoding for Password5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:H/I:H/A:H
48COMMENDWS 303VCM1.7CVE-2024-22182CWE-261: Weak Encoding for Password5.7CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:N/A:N
49COMMENDWS 303VCM1.7CVE-2024-21767CWE-284: Improper Access Control9.4CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:H/A:H
50COMMENDWS 303VCM1.7CVE-2024-23492CWE-88: Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:L/A:H
51DEXGATEDEXGate20130114CVE-2023-40153CWE-79: Improper neutralization of Input During Web Page Generation (‘Cross-site Scripting’)5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:N
52DEXGATEDEXGate20130114CVE-2023-42435CWE-352: Cross-Site Request Forgery (CSRF)5.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/
S:U/C:L/I:L/A:L
53DEXGATEDEXGate20130114CVE-2023-41089CWE-287: Improper Authentication8CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:H/A:H
54DEXGATEDEXGate20130114CVE-2023-41088CWE-319: Cleartext Transmission of Sensitive Information6.3CVSS:3.1/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:L/A:N
55DEXGATEDEXGate20130114CVE-2023-42666CWE-200: Exposure of Sensitive Information to an Unauthorized Actor5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:N/A:N
56SOCOMECMOD3GP-SY-120K CVE-2023-38582CWE-79: Improper neutralization of Input During Web Page Generation (‘Cross-site Scripting’)6.3CVSS:3.1AV:N/AC:L/PR:N/UI:R/
S:U/C:L/I:L/A:L
57SOCOMECMOD3GP-SY-120K CVE-2023-39446CWE-352: Cross-Site Request Forgery (CSRF)8.9CVSS:3.1AV:N/AC:L/PR:L/UI:R/
S:C/C:L/I:H/A:H
58SOCOMECMOD3GP-SY-120K CVE-2023-41965CWE-922: Insecure Storage of Sensitive Information7.5CVSS:3.1AV:N/AC:L/PR:N/UI:N/
S:U/C:H/I:N/A:N
59SOCOMECMOD3GP-SY-120K CVE-2023-41084CWE-565: Reliance on Cookies without Validation and Integrity Checking10CVSS:3.1AV:N/AC:L/PR:N/UI:N/
S:C/C:H/I:H/A:H
60SOCOMECMOD3GP-SY-120K CVE-2023-40221CWE-94: Improper Control of Generation of Code (‘Code Injection’)8.8CVSS:3.1AV:N/AC:L/PR:N/UI:R/
S:U/C:H/I:H/A:H
61SOCOMECMOD3GP-SY-120K CVE-2023-39452CWE-256: Plaintext Storage of a Password7.5CVSS:3.1AV:N/AC:L/PR:N/UI:N/
S:U/C:H/I:N/A:N
62SOCOMECMOD3GP-SY-120K CVE-2023-38255CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)6.5CVSS:3.1AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:L/A:N
63EFACECBCU 500 CVE-2023-50707CWE-400: Uncontrolled Resource Consumption9.6CVSS:3.0/AV:N/AC:L/PR:L/UI:N/
S:C/C:N/I:H/A:H
64EFACECBCU 500 CVE-2023-6689CWE-352: Cross-Site Request Forgery (CSRF)8.2CVSS:3.0/AV:N/AC:L/PR:N/UI:R/
S:C/C:N/I:L/A:H
65EFACECBCU 500 CVE-2023-50703CWE-319: Cleartext Transmission of Sensitive Information6.3CVSS:3.0/AV:A/AC:L/PR:N/UI:R/
S:U/C:H/I:L/A:N
66EFACECBCU 500 CVE-2023-50704CWE-601: URL Redirection to untrusted site4.3CVSS:3.0/AV:P/AC:L/PR:N/UI:N/
S:U/C:L/I:L/A:L
67EFACECBCU 500 CVE-2023-50705CWE-200: Exposure of sensitive information5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/
S:U/C:L/I:N/A:N
68EFACECBCU 500 CVE-2023-50706CWE-284: Improper Access Control4.1CVSS:3.0/AV:P/AC:L/PR:L/UI:N/
S:U/C:L/I:L/A:L

POLICY DISCLOSURE

POLICY

Thales’ mission is to safeguard and enhance the business transformation of organizations by managing cybersecurity risk to protect their people and assets.

Thales is fully committed to achieving this mission through ethical and timely disclosure of vulnerability information.

Thanks to the research work of Thales’ research technicians, multiple vulnerabilities have been reported and published, leading Thales to become a CNA under the scope of a CNA-Root, with the consequent authorization to assign CVE identifiers to vulnerabilities detected by its research teams.

 

DISCLOSURE

With the discovery of the vulnerabilities and the report to Thales, the responsible parties will try to contact the affected vendor. The following aspects should be taken into account:

  • Initially, the contact will be made by e-mail against the affected supplier or through any secondary mechanism proposed by the supplier as long as it is secure.
  • Thales will arrange with the affected supplier a timeframe according to their situation.
  • Although there are such measures and publication times, Thales is complementarily committed to improving the cybersecurity of people and organizations, so to strengthen and improve relationships, it is committed whenever appropriate and acceptable, to provide suppliers with a draft of the notice prior to publication and to participate in a joint and coordinated manner throughout the process.

 

VULNERABILITY NOTIFICATION

Researchers shall comply with and review the following terms and conditions set forth below that affect products, equipment, applications or services being tested and include at a minimum the following information via secure email to the following address: cve.coordination.iberia@thalesgroup.com

  • Code and serial number of the device or software believed to be affected.
  • Version of the device or software being analyzed along with the full name or model.
  • Description of the behavior observed and the expected behavior that explains the vulnerability.
  • Detailed description of the process performed to reproduce the possible problem detected. In case the difficulty is high, it is suggested to send a video showing in detail the steps performed.
  • Impact or result of the problem, CVSS, CWE and authors.

After this first contact, Thales will provide the sender of the vulnerability with a tracking number for the treatment and follow-up of the process.

To contact the Thales team, please contact cve.coordination.iberia@thalesgroup.com in encrypted form.

Public PGP key for secure information exchange.

 

VULNERABILITY IDENTIFICATION

Thales reserves the right to analyze the report sent by the researcher to assess and split or simplify the problems detected on the product or software also determining whether or not they are vulnerabilities.

If they are vulnerabilities, Thales will proceed to register the ID assignments (CVE ID) always in conjunction and coordination with the affected vendor, but having Thales, the last word on the problem or vulnerability.

 

PUBLISHING

Thales will make every effort to ensure that the vulnerability’s associated vulnerability identifier (CVE ID) is assigned and published.

Thales will reserve the CVE ID after the vendor confirms the issues. The CVE assignment will be shared with the vendor as soon as possible. Once the advisories have been made public, MITRE and, where appropriate, the national computer emergency response teams will be informed.

Emergency incident response activation