CVE-2022-1401 : DEVICE42 ASSET MANAGEMENT APPLIANCE PRIOR 18.01.00 WRIMAGERESOURCE.ADX ACCESS CONTROL

Description

Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Device42 CMDB versions prior to 18.01.00.

References

https://www.bitdefender.com/blog/labs/a-red-team-perspective-on-the-device42-asset-management-appliance/

For More Information

MITRE

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-47767 : SOLAR-LOG GATEWAY UP TO 4.2.7/5.1.1 SLCORE BACKDOOR

CVE-2022-47767 : SOLAR-LOG GATEWAY UP TO 4.2.7/5.1.1 SLCORE BACKDOOR

Description A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker.

CVE-2022-45808 : LEARNPRESS PLUGIN UP TO 4.1.7.3.2 ON WORDPRESS SQL INJECTION

CVE-2022-45808 : LEARNPRESS PLUGIN UP TO 4.1.7.3.2 ON WORDPRESS SQL INJECTION

Description SQL Injection vulnerability in LearnPress – WordPress LMS Plugin

CVE-2023-21795 : MICROSOFT EDGE REMOTE CODE EXECUTION

CVE-2023-21795 : MICROSOFT EDGE REMOTE CODE EXECUTION

Description Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21796. References https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21795 For More Information