Known vulnerabilities in Energy Management Controller with Cloud Services
Vendor:
Sharp Corporation
Software CPE:
cpe:2.3:a:sharp_corporation:energy_management_controller_with_cloud_services:*:*:*:*:*:*:*:*
Website:
https://jp.sharp/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86003 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-23789 |
CWE-78 | Medium | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU86002 - Server-Side Request Forgery (SSRF) CVE-2024-23788 |
CWE-918 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU86001 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-23787 |
CWE-22 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU86000 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-23786 |
CWE-79 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU85999 - Cross-Site Request Forgery (CSRF) CVE-2024-23785 |
CWE-352 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU85998 - Improper Access Control CVE-2024-23784 |
CWE-284 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |
||
| #VU85997 - Improper Authentication CVE-2024-23783 |
CWE-287 | Low | B0.2.0.0 | 01.02.2024 |
SB2024020136 |