CVE-2025-59392
- EPSS 0.03%
- Veröffentlicht 06.11.2025 00:00:00
- Zuletzt bearbeitet 04.02.2026 21:18:53
On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.
CVE-2024-46601
- EPSS 0.7%
- Veröffentlicht 07.01.2025 16:15:34
- Zuletzt bearbeitet 16.04.2025 15:13:39
Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.
CVE-2024-46602
- EPSS 0.09%
- Veröffentlicht 07.01.2025 16:15:34
- Zuletzt bearbeitet 16.04.2025 15:13:58
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.
CVE-2024-46603
- EPSS 0.09%
- Veröffentlicht 07.01.2025 16:15:34
- Zuletzt bearbeitet 16.04.2025 15:14:11
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
CVE-2024-22077
- EPSS 0.2%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 18:20:36
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.
CVE-2024-22078
- EPSS 0.24%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 18:20:45
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all ...
CVE-2024-22079
- EPSS 0.68%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 17:28:31
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.
CVE-2024-22080
- EPSS 0.51%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 17:28:50
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.
CVE-2024-22081
- EPSS 0.51%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 17:29:05
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.
CVE-2024-22082
- EPSS 0.31%
- Veröffentlicht 20.03.2024 05:15:45
- Zuletzt bearbeitet 16.04.2025 17:29:20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused be an attacker get a better understanding of the operating system.