cbcvebase.

Kiloview P1 P2 vulnerabilities

10 known vulnerabilities affecting kiloview/p1_p2.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-41917P2CRITICALCVSS 10.0≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41917 [CRITICAL] CWE-20 CVE-2023-41917: Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attac Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized code execution.
nvd
CVE-2023-41918P2CRITICALCVSS 10.0≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41918 [CRITICAL] CWE-306 CVE-2023-41918: A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attack A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functions, or even the execution of arbitrary code.
nvd
CVE-2023-41920P2CRITICALCVSS 9.8≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41920 [CRITICAL] CWE-305 CVE-2023-41920: The vulnerability allows attackers access to the root account without having to authenticate. Specif The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.
nvd
CVE-2023-41921P3CRITICALCVSS 9.8≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41921 [CRITICAL] CWE-494 CVE-2023-41921: A vulnerability allows attackers to download source code or an executable from a remote location and A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the system, thus achieving the modification of the target’s integrity to achi
nvd
CVE-2023-41919P3CRITICALCVSS 9.8≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41919 [CRITICAL] CWE-798 CVE-2023-41919: Hardcoded credentials are discovered within the application's source code, creating a potential secu Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.
nvd
CVE-2023-41926P3HIGHCVSS 8.8≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41926 [HIGH] CWE-522 CVE-2023-41926: The webserver utilizes basic authentication for its user login to the configuration interface. As en The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.
nvd
CVE-2023-41923P3HIGHCVSS 7.2≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41923 [HIGH] CWE-521 CVE-2023-41923: The user management section of the web application permits the creation of user accounts with excess The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.
nvd
CVE-2023-41922P4MEDIUMCVSS 5.4≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41922 [MEDIUM] CWE-79 CVE-2023-41922: A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in multiple instances of Stored XSS vulner
nvd
CVE-2023-41928P4MEDIUMCVSS 5.3≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41928 [MEDIUM] CWE-327 CVE-2023-41928: The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weak The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.
nvd
CVE-2023-41927P4MEDIUMCVSS 5.3≥ All, ≤ 4.8.26052024-07-02
CVE-2023-41927 [MEDIUM] CWE-327 CVE-2023-41927: The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be ph The server supports at least one cipher suite which is on the NCSC-NL list of cipher suites to be phased out, increasing the risk of cryptographic weaknesses.
nvd
Kiloview P1 P2 vulnerabilities | cvebase