CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.
Boundary, Consul, Consul_docker_image, Consul_template, Go-getter, Go-slug, Nomad, Packer, Sentinel, Terraform
2021-07-29
N/A
8.8 HIGH
HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API requests executed using the run token, allowing privilege escalation to organization owner. Fixed in v202107-1.
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
Sandisk_x600_sd9tb8w-128g_firmware, Sandisk_x600_sd9tb8w-128g, Sandisk_x600_sd9tb8w-256g_firmware, Sandisk_x600_sd9tb8w-256g, Sandisk_x600_sd9tb8w-512g_firmware, Sandisk_x600_sd9tb8w-512g, Sandisk_x600_sd9tb8w-1t00_firmware, Sandisk_x600_sd9tb8w-1t00, Sandisk_x600_sd9tb8w-2t00_firmware, Sandisk_x600_sd9tb8w-2t00
2023-02-14
N/A
9.8 CRITICAL
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
Sandisk_x600_sd9tb8w-128g_firmware, Sandisk_x600_sd9tb8w-128g, Sandisk_x600_sd9tb8w-256g_firmware, Sandisk_x600_sd9tb8w-256g, Sandisk_x600_sd9tb8w-512g_firmware, Sandisk_x600_sd9tb8w-512g, Sandisk_x600_sd9tb8w-1t00_firmware, Sandisk_x600_sd9tb8w-1t00, Sandisk_x600_sd9tb8w-2t00_firmware, Sandisk_x600_sd9tb8w-2t00
2023-02-14
N/A
8.8 HIGH
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
Sandisk_x600_sd9tb8w-128g_firmware, Sandisk_x600_sd9tb8w-128g, Sandisk_x600_sd9tb8w-256g_firmware, Sandisk_x600_sd9tb8w-256g, Sandisk_x600_sd9tb8w-512g_firmware, Sandisk_x600_sd9tb8w-512g, Sandisk_x600_sd9tb8w-1t00_firmware, Sandisk_x600_sd9tb8w-1t00, Sandisk_x600_sd9tb8w-2t00_firmware, Sandisk_x600_sd9tb8w-2t00
2023-02-14
N/A
9.8 CRITICAL
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
