CVE-2024-41146
- EPSS 0.1%
- Veröffentlicht 12.12.2024 02:15:22
- Zuletzt bearbeitet 12.12.2024 02:15:22
Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected...
CVE-2024-24972
- EPSS 0.29%
- Veröffentlicht 11.09.2024 04:15:05
- Zuletzt bearbeitet 11.09.2024 16:26:11
Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, causing a Denial of Service. Gallagher recommend the di...
CVE-2024-39808
- EPSS 0.13%
- Veröffentlicht 11.09.2024 04:15:05
- Zuletzt bearbeitet 11.09.2024 16:26:11
Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot leading to a denial of service. This issue affects...
CVE-2024-23906
- EPSS 0.21%
- Veröffentlicht 11.09.2024 04:15:03
- Zuletzt bearbeitet 11.09.2024 16:26:11
Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an authenticated Operator's session. This issue affe...
CVE-2024-23317
- EPSS 0.04%
- Veröffentlicht 11.07.2024 03:15:03
- Zuletzt bearbeitet 21.11.2024 08:57:29
External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution. This issue affects: 9.10 prior to vCR9.10.240520a (distributed in ...
CVE-2024-23485
- EPSS 0.05%
- Veröffentlicht 11.07.2024 03:15:03
- Zuletzt bearbeitet 21.11.2024 08:57:48
Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks connected via Aperio Communication Hubs to momentarily allow free access. ...
CVE-2024-22387
- EPSS 0.12%
- Veröffentlicht 11.07.2024 03:15:02
- Zuletzt bearbeitet 21.11.2024 08:56:10
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O connections leading to unexpected behavior that in some circumstances could compro...