ZeroHour

Vulnerabilities

61 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-55515
+3 in the same advisory: …55516 …55513 …55514
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90.

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.

NVD description · AI analysis pending
9.8
group max
<1%
  • raisecom msg2300 firmware
  • raisecom msg2100e firmware
  • raisecom msg2200 firmware
  • +1 more
CVE-2024-7732
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

NVD description · AI analysis pending
9.8<1%
  • secom dr.id attendance system
CVE-2024-7731
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

NVD description · AI analysis pending
9.8<1%
  • secom dr.id access control
CVE-2024-7470
+3 in the same advisory: …7469 …7468 …7467
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90.

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function sslvpn_config_mod of the file /vpn/vpn_template_style.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273563. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.325% PoC
  • raisecom msg2300 firmware
  • raisecom msg2100e firmware
  • raisecom msg2200 firmware
  • +1 more
CVE-2024-7120
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90.

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.

NVD description · AI analysis pending
5.393% PoC
  • raisecom msg2300 firmware
  • raisecom msg2100e firmware
  • raisecom msg2200 firmware
  • +1 more
CVE-2023-2912
Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.

Use After Free vulnerability in Secomea SiteManager Embedded allows Obstruction.

NVD description · AI analysis pending
7.5<1%
  • secomea sitemanager embedded
CVE-2022-4308
+1 in the same advisory: …0317
Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteManager, if the generated file is leaked.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager
CVE-2022-38125
Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.

Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modules) allows Exploiting Trust in Client.

NVD description · AI analysis pending
5.5<1%
  • secomea sitemanager 3549 firmware
  • secomea sitemanager 3539 firmware
  • secomea sitemanager 3529 firmware
  • +1 more
CVE-2022-38124
Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

NVD description · AI analysis pending
6.5<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 3329 firmware
  • secomea sitemanager 1529 firmware
  • +1 more
CVE-2022-2752
A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions.

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

NVD description · AI analysis pending
7.8<1%
  • secomea gatemanager
CVE-2022-38123
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager in

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.

NVD description · AI analysis pending
7.2<1%
  • secomea gatemanager
CVE-2022-25786
Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information.

Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensitive information. This issue affects: GateManager all versions prior to 9.7.

NVD description · AI analysis pending
4.9<1%
  • secomea gatemanager
CVE-2022-25778
Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • secomea gatemanager 8250 firmware
  • +1 more
CVE-2021-32010
+2 in the same advisory: …25785 …25784
Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks.

Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitate man in the middle attacks. This issue affects: Secomea SiteManager All versions prior to 9.7. Secomea LinkManager versions prior to 9.7. Secomea GateManager versions prior to 9.7.

NVD description · AI analysis pending
8.1
group max
<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2022-26671
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code.

Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

NVD description · AI analysis pending
7.3<1%
  • secom dr.id access control
  • secom dr.id attendance system
CVE-2021-32009
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session.

Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

NVD description · AI analysis pending
6.1<1%
  • secomea gatemanager
CVE-2021-32006
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup files.

NVD description · AI analysis pending
4.3<1%
  • secomea gatemanager
CVE-2021-32005
Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution.

Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions.

NVD description · AI analysis pending
5.4<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2021-32008
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.

This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

NVD description · AI analysis pending
8.7<1%
  • secomea gatemanager
CVE-2021-32004
This issue affects: Secomea GateManager All versions prior to 9.6.

This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

NVD description · AI analysis pending
5.3<1%
  • secomea gatemanager 8250 firmware
CVE-2021-32003
+1 in the same advisory: …32002
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

NVD description · AI analysis pending
5.5
group max
<1%
  • secomea sitemanager firmware
CVE-2021-35962
Specific page parameters in Dr.

Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter special characters. Remote attackers can apply Path Traversal means to download credential files from the system without permission.

NVD description · AI analysis pending
7.52%
  • secom door access control
  • secom personnel attendance system
CVE-2021-35961
Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the sy

Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.

NVD description · AI analysis pending
9.82%
  • secom dr.id access control
CVE-2020-29030
+2 in the same advisory: …29029 …29028
Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code.

Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4.

NVD description · AI analysis pending
8.8
group max
<1%
  • secomea gatemanager firmware
CVE-2020-29020
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured c

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.

NVD description · AI analysis pending
7.22%
  • secomea sitemanager firmware
CVE-2020-29032
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on serve

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

NVD description · AI analysis pending
7.2<1%
  • secomea gatemanager 8250 firmware
CVE-2020-29027
Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack.

Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.

NVD description · AI analysis pending
5.4<1%
  • secomea sitemanager 1129 firmware
  • secomea sitemanager 1139 firmware
  • secomea sitemanager 1149 firmware
  • +1 more
CVE-2020-29025
A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause Ja

A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3

NVD description · AI analysis pending
6.1<1%
  • secomea sitemanager embedded
CVE-2020-29022
+2 in the same advisory: …29024 …29023
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks.

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3

NVD description · AI analysis pending
5.3
group max
<1%
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • secomea gatemanager 9250 firmware
  • +1 more
CVE-2020-29031
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any us

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to 9.2c

NVD description · AI analysis pending
8.1<1%
  • secomea gatemanager 8250 firmware
  • secomea gatemanager 4250 firmware
  • secomea gatemanager 4260 firmware
  • +1 more