ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33468
+1 in the same advisory: …33469
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device.

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • kramerav via go2 firmware
  • kramerav via connect2 firmware
CVE-2023-33508
+2 in the same advisory: …33509 …33507
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).

KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).

NVD description · AI analysis pending
9.8
group max
1% PoC
  • kramerav via go2 firmware
CVE-2021-36356
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an incomplete fix for CVE-2019-17124.

NVD description · AI analysis pending
9.854% PoC
  • kramerav viaware
CVE-2021-35064
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo.

KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

NVD description · AI analysis pending
9.871% PoC ×2
  • kramerav viaware
CVE-2019-17124
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

NVD description · AI analysis pending
9.823% PoC ×2
  • kramerav viaware