Jacob Baines

#713de 53,635
270.6CVSS total
Vulnerabilidades · 32
Média
1
Alta
20
Crítica
11
PT-2022-4220
8.8
2022-06-28
Yokogawa · Cams For His · CVE-2022-30707
**Nome do software vulnerável e versões afetadas** CENTUM CS 3000, versões R3.08.10 a R3.09.00 CENTUM VP, versões R4.01.00 a R4.03.00 CENTUM VP, versões R5.01.00 a R5.04.20 Versões do CENTUM VP de R6.01.00 a R6.09.00 Versões do Exaopc de R3.72.00 a R3.80.00 Versões do B/M9000 CS de R5.04.01 a R5.05.01 Versões do B/M9000 VP de R6.01.01 a R8.03.01 **Descrição** O problema está relacionado a uma violação dos princípios de design seguro na comunicação do CAMS for HIS. Um invasor próximo pode comprometer um computador que utilize o software CAMS for HIS e usar as credenciais da máquina comprometida para acessar dados de outra máquina que utilize o software CAMS for HIS. Isso pode levar à desativação das funções do software CAMS for HIS em qualquer máquina afetada, ou à divulgação/alteração de informações. **Recomendações** Para as versões do CENTUM CS 3000 de R3.08.10 a R3.09.00, atualize para uma versão fora desse intervalo para mitigar o risco. Para as versões do CENTUM VP de R4.01.00 a R4.03.00, atualize para uma versão fora desse intervalo para mitigar o risco. Para as versões do CENTUM VP R5.01.00 a R5.04.20, atualize para uma versão fora desse intervalo para mitigar o risco. Para as versões do CENTUM VP R6.01.00 a R6.09.00, atualize para uma versão fora desse intervalo para mitigar o risco. Para as versões do Exaopc R3.72.00 a R3.80.00, atualize para uma versão fora desse intervalo para mitigar o risco, mas somente se o NTPF100-S6 ‘Para o CENTUM VP Support CAMS para HIS’ estiver instalado. Para as versões do B/M9000 CS
PT-2019-16798
7.5
2019-07-29
Dahua · Dahua Ipc Hx5X3X · CVE-2019-3948
**Name of the Vulnerable Software and Affected Versions** Amcrest IP2M-841B version 2.520.AC00.18.R Dahua IPC-XXBXX version 2.622.0000000.9.R Dahua IPC HX5X3X and HX4X3X version 2.800.0000008.0.R Dahua DH-IPC HX883X and DH-IPC-HX863X version 2.622.0000000.7.R Dahua DH-SD4XXXXX version 2.623.0000000.7.R Dahua DH-SD5XXXXX version 2.623.0000000.1.R Dahua DH-SD6XXXXX versions 2.623.0000000.1.R through 2.640.0000000.2.R Dahua NVR5XX-4KS2 version 3.216.0000006.0.R Dahua NVR4XXX-4KS2 version 3.216.0000006.0.R Dahua NVR2XXX-4KS2 (affected versions not specified) **Description** The issue allows an unauthenticated, remote person to access the HTTP endpoint "/videotalk" without requiring authentication. This could potentially allow the person to listen to the audio of the capturing device. **Recommendations** For Amcrest IP2M-841B version 2.520.AC00.18.R, consider disabling access to the "/videotalk" endpoint until a patch is available. For Dahua IPC-XXBXX version 2.622.0000000.9.R, restrict access to the "/videotalk" endpoint to minimize the risk of exploitation. For Dahua IPC HX5X3X and HX4X3X version 2.800.0000008.0.R, avoid using the "/videotalk" endpoint until the issue is resolved. For Dahua DH-IPC HX883X and DH-IPC-HX863X version 2.622.0000000.7.R, consider implementing authentication for the "/videotalk" endpoint as a temporary workaround. For Dahua DH-SD4XXXXX version 2.623.0000000.7.R, restrict access to the "/videotalk" endpoint to minimize the risk of exploitation. For Dahua DH-SD5XXXXX version 2.623.0000000.1.R, avoid using the "/videotalk" endpoint until the issue is resolved. For Dahua DH-SD6XXXXX versions 2.623.0000000.1.R through 2.640.0000000.2.R, consider disabling access to the "/videotalk" endpoint until a patch is available. For Dahua NVR5XX-4KS2 version 3.216.0000006.0.R, restrict access to the "/videotalk" endpoint to minimize the risk of exploitation. For Dahua NVR4XXX-4KS2 version 3.216.0000006.0.R, avoid using the "/videotalk" endpoint until the issue is resolved. For Dahua NVR2XXX-4KS2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2019-16783
10
2019-04-30
Extron · Extron Sharelink 200/250 · CVE-2019-3929
**Name of the Vulnerable Software and Affected Versions** Crestron AM-100 version 1.6.0.2 Crestron AM-101 version 2.7.0.1 Barco wePresent WiPG-1000P version 2.3.0.10 Barco wePresent WiPG-1600W versions prior to 2.4.1.19 Extron ShareLink 200/250 version 2.0.3.4 Teq AV IT WIPS710 version 1.1.0.7 SHARP PN-L703WA version 1.4.2.3 Optoma WPS-Pro version 1.0.0.5 Blackbox HD WPS version 1.0.0.5 InFocus LiteShow3 version 1.0.16 InFocus LiteShow4 version 2.0.0.7 **Description** The issue allows a remote, unauthenticated attacker to execute operating system commands as root via command injection through the "file transfer.cgi" HTTP endpoint. **Recommendations** For Crestron AM-100 version 1.6.0.2, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Crestron AM-101 version 2.7.0.1, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Barco wePresent WiPG-1000P version 2.3.0.10, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Barco wePresent WiPG-1600W versions prior to 2.4.1.19, update to firmware 2.4.1.19 or later. For Extron ShareLink 200/250 version 2.0.3.4, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Teq AV IT WIPS710 version 1.1.0.7, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For SHARP PN-L703WA version 1.4.2.3, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Optoma WPS-Pro version 1.0.0.5, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For Blackbox HD WPS version 1.0.0.5, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For InFocus LiteShow3 version 1.0.16, consider disabling access to the "file transfer.cgi" endpoint until a patch is available. For InFocus LiteShow4 version 2.0.0.7, consider disabling access to the "file transfer.cgi" endpoint until a patch is available.