Known vulnerabilities in VAR600-H
Vendor:
Vonets
Software:
VAR600-H
Software CPE:
cpe:2.3:h:vonets:var600-h:*:*:*:*:*:*:*:*
Website:
https://www.vonets.com/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU95164 - Direct Request ('Forced Browsing') CVE-2024-42001 |
CWE-425 | High | - | 02.08.2024 |
SB2024080225 |
||
| #VU95162 - Stack-based buffer overflow CVE-2024-39791 |
CWE-121 | High | - | 02.08.2024 |
SB2024080225 |
||
| #VU95161 - Improper Check or Handling of Exceptional Conditions CVE-2024-39815 |
CWE-703 | Medium | - | 02.08.2024 |
SB2024080225 |
||
| #VU95158 - Command injection CVE-2024-37023 |
CWE-77 | Low | - | 02.08.2024 |
SB2024080225 |
||
| #VU95156 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-41936 |
CWE-22 | Medium | - | 02.08.2024 |
SB2024080225 |
||
| #VU95155 - Improper Access Control CVE-2024-29082 |
CWE-284 | High | - | 02.08.2024 |
SB2024080225 |
||
| #VU95154 - Use of Hard-coded Credentials CVE-2024-41161 |
CWE-798 | Medium | - | 02.08.2024 |
SB2024080225 |