CVE List - Iberia
| ID | Manufacturer | Device | Firmware | CVE ID | CWE | Score | CVSS Vector |
|---|---|---|---|---|---|---|---|
| 1 | ZIV | 4CCT-EA6-334126BF | 3.23.80.27.36371 | CVE-2021-25909 | CWE-400: Uncontrolled Resource Consumption | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:C/C:N/I:N/A:H |
| 2 | ZIV | 4CCT-EA6-334126BF | 3.23.77.8.33251 | CVE-2021-25910 | CWE-287: Improper Authentication | 8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A:H |
| 3 | CIRCUTOR | SGE-PLC1000 | 0.9.2b | CVE-2021-33841 | CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) | 10 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A:H |
| 4 | CIRCUTOR | SGE-PLC1000 | 0.9.2b | CVE-2021-33842 | CWE-565: Reliance on Cookies without Validation and Integrity Checking | 8.8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A: |
| 5 | CIRCUTOR | SGE-PLC1000 | 0.9.2b | CVE-2011-0762 CVE-2011-2191 CVE-2012-0920 | Several CVE | 10 | |
| 6 | SITEL | CAP/PRX | 5.2.01 | CVE-2021-32453 | CWE-306: Missing Authentication for Critical Function | 6.5 | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:H |
| 7 | SITEL | CAP/PRX | 5.2.01 | CVE-2021-32455 | CWE-400: Uncontrolled Resource Consumption | 6.5 | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:H |
| 8 | SITEL | CAP/PRX | 5.2.01 | CVE-2021-32454 | CWE-798: Use of Hard-coded Credentials | 9.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 9 | ZIGOR | ZIGOR TPS200 NG | 2.00 | CVE-2020-8973 | CWE-284: Improper Access Control | 9.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 10 | ZIGOR | ZIGOR TPS200 NG | 2.00 | CVE-2020-8974 | CWE-434: Unrestricted upload of file with dangerious type | 10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 11 | ZIGOR | ZIGOR TPS200 NG | 2.00 | CVE-2020-8975 | CWE-201: Exposure of Sensitive Information Through Sent Data | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 12 | ZIGOR | ZIGOR TPS200 NG | 2.00 | CVE-2020-8976 | CWE-352: Cross-Site Request Forgery (CSRF) | 9.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 13 | SITEL | CAP/PRX | 5.2.01 | CVE-2021-32456 | CWE-319: Transmisión de información sensible en texto claro | 6.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/ S:U/C:H/I:N/A:N |
| 14 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47553 | CWE-285: Improper Authorization | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 15 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47554 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 8.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:L/A:N |
| 16 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47555 | CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) | 9.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 17 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47562 | CWE-770: Allocation of Resources Without Limits or Throttling | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 18 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47556 | CWE-400: Uncontrolled Resource Consumption | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 19 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47557 | CWE-916: Use of Password Hash With Insufficient Computational Effort | 6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:L/A:N |
| 20 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47558 | CWE-284: Improper Access Control | 9.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 21 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47559 | CWE-352: Cross-Site Request Forgery (CSRF) | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 22 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47560 | CWE-319: Cleartext Transmission of Sensitive Information | 5.7 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:L/A:N |
| 23 | ORMAZABAL | ekorCCP | 601j | CVE-2022-47561 | CWE-256: Unprotected Storage of Credentials | 7.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/ S:U/C:H/I:L/A:L |
| 24 | INGETEAM | INGEPAC DA | Linux IngepacDA 3.2.0-rt10_DA_1.0.0.21 #315 PREEMPT RT Wed Jul 15 13:17:29 CEST 2015 armv7l | CVE-2017-20007 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:N/A:N |
| 25 | DIGI | Digi ConnectPort® X2D | 2.22.1 | CVE-2022-2634 | CWE-250: Execution with Unnecessary Privileges | 10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H |
| 26 | IPCOMM | ipDIO | 3.9 2016/04/18 / IPDIO_SW_3.9 | CVE-2022-24432 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:L/I:L/A:L |
| 27 | IPCOMM | ipDIO | 3.9 2016/04/18 / IPDIO_SW_3.9 | CVE-2022-21146 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 6.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:U/C:L/I:L/A:L |
| 28 | IPCOMM | ipDIO | 3.9 2016/04/18 / IPDIO_SW_3.9 | CVE-2022-24915 | CWE-94: Improper Control of Generation of Code (‘Code Injection’) | 8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:H/I:H/A:H |
| 29 | IPCOMM | ipDIO | 3.9 2016/04/18 / IPDIO_SW_3.9 | CVE-2022-22985 | CWE-94: Improper Control of Generation of Code (‘Code Injection’) | 8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A:H |
| 30 | SIEMENS | Spectrum Power™ 4 | Spectrum Power™ 4 (Spectrum Power 4.7 Service Pack 3) | CVE-2022-23312 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:U/C:L/I:L/A:N |
| 31 | SIEMENS | RSG908C | v5.5.4 | CVE-2022-34663 | CWE-94: Improper Control of Generation of Code (‘Code Injection’) | 8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:H/I:H/A:H |
| 32 | INGETEAM | INGEPAC DA3451 | 0.29.2.42 | CVE-2023-3768 | CWE-20: Improper input validation | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:N/I:N/A:H |
| 33 | INGETEAM | NGEPAC EF MDFC5066 | 0.22.6+6.1.1.22+5.3.1.1 | CVE-2023-3769 | CWE-20: Improper input validation | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:C/C:N/I:N/A:H |
| 34 | INGETEAM | INGEPAC DA3451 | 0.29.2.42 | CVE-2023-3770 | CWE-20: Improper input validation | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:N/A:N |
| 35 | LANDIS | E580 Landis+Gyr ZMQ202 | E65CXE-2.2.0-build-20210503.160 | CVE-2022-3083 | CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax | 3.9 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/ S:C/C:N/I:L/A:L |
| 36 | SAUTER | Sauter nova 200 – 2200 Series | Version 4.2.1.0 Dev. | CVE-2023-0053 | CWE-319: Cleartext Transmission of Sensitive Information | 5.7 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:N/A:N |
| 37 | SAUTER | Sauter nova 200 – 2200 Series | Version 4.2.1.0 Dev. | CVE-2023-0052 | CWE-250: Execution with Unnecessary Privileges | 9.8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/ S:U/C:H/I:H/A:H |
| 38 | SOCOMEC | MODULYS GP Green Power 2.0 | Netvision v7.20 | CVE-2023-0356 | CWE-261: Weak Encoding for Password | 7.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:N/A:N |
| 39 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-40143 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:N |
| 40 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-45222 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:N |
| 41 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-42765 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:N |
| 42 | WESTERMO | Lynx 206-F2G | 4.24.1 1.17.2 | CVE-2023-45227 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:N |
| 43 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-40544 | CWE-319: Cleartext Transmission of Sensitive Information | 5.7 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:N/A:N |
| 44 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-45213 | CWE-942: Permissive Cross-domain Policy with Untrusted Domains | 6.5 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:C/C:H/I:N/A:N |
| 45 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-45735 | CWE-94: Improper Control of Generation of Code (‘Code Injection’) | 8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:H/I:H/A:H |
| 46 | WESTERMO | Lynx 206-F2G | 4.24.1 | CVE-2023-38579 | CWE-352: Cross-Site Request Forgery (CSRF) | 8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:H/I:H/A:H |
| 47 | LANTRONIX | Xport | Device Server Configuration Manager version 1.8.0.1 | CVE-2023-7237 | CWE-261: Weak Encoding for Password | 5.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:H/I:H/A:H |
| 48 | COMMEND | WS 303VCM | 1.7 | CVE-2024-22182 | CWE-261: Weak Encoding for Password | 5.7 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:N/A:N |
| 49 | COMMEND | WS 303VCM | 1.7 | CVE-2024-21767 | CWE-284: Improper Access Control | 9.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:H/A:H |
| 50 | COMMEND | WS 303VCM | 1.7 | CVE-2024-23492 | CWE-88: Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:L/A:H |
| 51 | DEXGATE | DEXGate | 20130114 | CVE-2023-40153 | CWE-79: Improper neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:N |
| 52 | DEXGATE | DEXGate | 20130114 | CVE-2023-42435 | CWE-352: Cross-Site Request Forgery (CSRF) | 5.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/ S:U/C:L/I:L/A:L |
| 53 | DEXGATE | DEXGate | 20130114 | CVE-2023-41089 | CWE-287: Improper Authentication | 8 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A:H |
| 54 | DEXGATE | DEXGate | 20130114 | CVE-2023-41088 | CWE-319: Cleartext Transmission of Sensitive Information | 6.3 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:L/A:N |
| 55 | DEXGATE | DEXGate | 20130114 | CVE-2023-42666 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:N/A:N |
| 56 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-38582 | CWE-79: Improper neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 6.3 | CVSS:3.1AV:N/AC:L/PR:N/UI:R/ S:U/C:L/I:L/A:L | |
| 57 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-39446 | CWE-352: Cross-Site Request Forgery (CSRF) | 8.9 | CVSS:3.1AV:N/AC:L/PR:L/UI:R/ S:C/C:L/I:H/A:H | |
| 58 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-41965 | CWE-922: Insecure Storage of Sensitive Information | 7.5 | CVSS:3.1AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:N/A:N | |
| 59 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-41084 | CWE-565: Reliance on Cookies without Validation and Integrity Checking | 10 | CVSS:3.1AV:N/AC:L/PR:N/UI:N/ S:C/C:H/I:H/A:H | |
| 60 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-40221 | CWE-94: Improper Control of Generation of Code (‘Code Injection’) | 8.8 | CVSS:3.1AV:N/AC:L/PR:N/UI:R/ S:U/C:H/I:H/A:H | |
| 61 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-39452 | CWE-256: Plaintext Storage of a Password | 7.5 | CVSS:3.1AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:N/A:N | |
| 62 | SOCOMEC | MOD3GP-SY-120K | CVE-2023-38255 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 6.5 | CVSS:3.1AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:L/A:N | |
| 63 | EFACEC | BCU 500 | CVE-2023-50707 | CWE-400: Uncontrolled Resource Consumption | 9.6 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/ S:C/C:N/I:H/A:H | |
| 64 | EFACEC | BCU 500 | CVE-2023-6689 | CWE-352: Cross-Site Request Forgery (CSRF) | 8.2 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/ S:C/C:N/I:L/A:H | |
| 65 | EFACEC | BCU 500 | CVE-2023-50703 | CWE-319: Cleartext Transmission of Sensitive Information | 6.3 | CVSS:3.0/AV:A/AC:L/PR:N/UI:R/ S:U/C:H/I:L/A:N | |
| 66 | EFACEC | BCU 500 | CVE-2023-50704 | CWE-601: URL Redirection to untrusted site | 4.3 | CVSS:3.0/AV:P/AC:L/PR:N/UI:N/ S:U/C:L/I:L/A:L | |
| 67 | EFACEC | BCU 500 | CVE-2023-50705 | CWE-200: Exposure of sensitive information | 5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/ S:U/C:L/I:N/A:N | |
| 68 | EFACEC | BCU 500 | CVE-2023-50706 | CWE-284: Improper Access Control | 4.1 | CVSS:3.0/AV:P/AC:L/PR:L/UI:N/ S:U/C:L/I:L/A:L |
POLICY DISCLOSURE
POLICY
Thales’ mission is to safeguard and enhance the business transformation of organizations by managing cybersecurity risk to protect their people and assets.
Thales is fully committed to achieving this mission through ethical and timely disclosure of vulnerability information.
Thanks to the research work of Thales’ research technicians, multiple vulnerabilities have been reported and published, leading Thales to become a CNA under the scope of a CNA-Root, with the consequent authorization to assign CVE identifiers to vulnerabilities detected by its research teams.
DISCLOSURE
With the discovery of the vulnerabilities and the report to Thales, the responsible parties will try to contact the affected vendor. The following aspects should be taken into account:
- Initially, the contact will be made by e-mail against the affected supplier or through any secondary mechanism proposed by the supplier as long as it is secure.
- Thales will arrange with the affected supplier a timeframe according to their situation.
- Although there are such measures and publication times, Thales is complementarily committed to improving the cybersecurity of people and organizations, so to strengthen and improve relationships, it is committed whenever appropriate and acceptable, to provide suppliers with a draft of the notice prior to publication and to participate in a joint and coordinated manner throughout the process.
VULNERABILITY NOTIFICATION
Researchers shall comply with and review the following terms and conditions set forth below that affect products, equipment, applications or services being tested and include at a minimum the following information via secure email to the following address: cve.coordination.iberia@thalesgroup.com
- Code and serial number of the device or software believed to be affected.
- Version of the device or software being analyzed along with the full name or model.
- Description of the behavior observed and the expected behavior that explains the vulnerability.
- Detailed description of the process performed to reproduce the possible problem detected. In case the difficulty is high, it is suggested to send a video showing in detail the steps performed.
- Impact or result of the problem, CVSS, CWE and authors.
After this first contact, Thales will provide the sender of the vulnerability with a tracking number for the treatment and follow-up of the process.
To contact the Thales team, please contact cve.coordination.iberia@thalesgroup.com in encrypted form.
Public PGP key for secure information exchange.
VULNERABILITY IDENTIFICATION
Thales reserves the right to analyze the report sent by the researcher to assess and split or simplify the problems detected on the product or software also determining whether or not they are vulnerabilities.
If they are vulnerabilities, Thales will proceed to register the ID assignments (CVE ID) always in conjunction and coordination with the affected vendor, but having Thales, the last word on the problem or vulnerability.
PUBLISHING
Thales will make every effort to ensure that the vulnerability’s associated vulnerability identifier (CVE ID) is assigned and published.
Thales will reserve the CVE ID after the vendor confirms the issues. The CVE assignment will be shared with the vendor as soon as possible. Once the advisories have been made public, MITRE and, where appropriate, the national computer emergency response teams will be informed.