A vulnerability was found in Altus Nexto NX3003, Nexto NX3004, Nexto NX3005, Nexto NX3010, Nexto NX3020, Nexto NX3030, Nexto NX5100, Nexto NX5101, Nexto NX5110, Nexto NX5210, Nexto Xpress XP300, Nexto Xpress XP315, Nexto Xpress XP325, Nexto Xpress XP340 and Hadron Xtorm HX3040. It has been declared as critical. Affected by this vulnerability is some unknown processing of the file getlogs.cgi of the component Parameter Handler. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
Altus Hadron Xtorm HX3040 Parameter getlogs.cgi command injection
- Virtual Patching
- August 23, 2021
- 12:04 pm
CVE-2023-4291 : Frauscher Sensortechnik FDS101 For FAdC 1.4.24 Code Injection
Description Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE)
CVE-2023-2163 : Linux Kernel 5.4 BPF kernel/bpf/verifier.c backtrack_insn calculation
Description Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe,
CVE-2023-42454 : SQLpage Up To 0.11.0 Database Connection String sqlpage/sqlpage.json Information Disclosure
Description SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly,