ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-42056
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data.

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

NVD description · AI analysis pending
6.5<1%
  • retool retool
CVE-2023-5908
+1 in the same advisory: …5909
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

NVD description · AI analysis pending
9.1
group max
<1%
  • ge industrial gateway server
  • ge keepserverex
  • ge opc-aggregator
  • +1 more
CVE-2022-2825
+1 in the same advisory: …2848
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.

NVD description · AI analysis pending
9.8
group max
3%
  • ge industrial gateway server
  • ge kepware kepserverex
  • ge opc-aggregator
  • +1 more
CVE-2020-27265
+2 in the same advisory: …27267 …27263
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server:

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and remotely execute code.

NVD description · AI analysis pending
9.8
group max
10%
  • ge industrial gateway server
  • ge kepware kepserverex
  • ge opc-aggregator
  • +1 more