Vulnerabilidades em Siretta

64 resultados
Análise Vexday

Com 64 CVEs catalogadas, a superfície de vulnerabilidades da Siretta apresenta, até o momento, ausência de registros no catálogo CISA KEV, o que coloca sua taxa de exploração ativa abaixo da média geral do catálogo. Ainda assim, 7 vulnerabilidades são classificadas como críticas, o que exige atenção contínua por parte de operadores e integradores. O tipo de falha mais recorrente é CWE-120 (buffer overflow clássico), uma categoria historicamente associada a impactos severos de execução de código e corrupção de memória. A CVE mais perigosa em destaque, CVE-2022-38066, possui score EPSS de 0,0709, indicando probabilidade baixa, porém não desprezível, de exploração ativa no curto prazo — recomendando-se priorização no ciclo de patching.

CVE-2022-38066HIGHAn OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafEPSS 7.1%CVE-2022-42484CRITICALAn OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP requesEPSS 6.0%CVE-2022-40969HIGHAn os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specialEPSS 5.8%CVE-2022-40222CRITICALAn OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speciEPSS 4.3%CVE-2022-40220HIGHAn OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speEPSS 4.1%CVE-2022-38459HIGHA stack-based buffer overflow vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A EPSS 3.9%CVE-2022-38715HIGHA leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-cEPSS 3.7%CVE-2022-39045HIGHA file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HEPSS 3.7%CVE-2022-42493CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.5%CVE-2022-42490CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.5%CVE-2022-42492CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.2%CVE-2022-42491CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.2%CVE-2022-36279HIGHA stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sEPSS 3.2%CVE-2022-41030HIGHSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210EPSS 2.7%CVE-2022-40701MEDIUMA directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speciallyEPSS 2.6%CVE-2022-41028HIGHSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210EPSS 2.4%CVE-2022-38088MEDIUMA directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A speciallEPSS 2.3%CVE-2022-41029HIGHSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210EPSS 2.2%CVE-2022-41027HIGHSeveral stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210EPSS 2.2%CVE-2022-38451MEDIUMA directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request canEPSS 2.1%