Sealevel

Seaconnect 370w Firmware

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 14.04.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:20

An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

Exploit
  • EPSS 1.88%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to tri...

Exploit
  • EPSS 1.88%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger t...

Exploit
  • EPSS 1.9%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a ...

  • EPSS 0.13%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:19

A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger ...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:20

A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to t...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:20

A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to tri...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 04.02.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 05:49:20

An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload glob...