CVE-2026-58479
- EPSS 2.77%
- Veröffentlicht 14.07.2026 14:44:49
- Zuletzt bearbeitet 14.07.2026 23:17:32
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system comma...
CVE-2026-58478
- EPSS 0.26%
- Veröffentlicht 14.07.2026 14:41:54
- Zuletzt bearbeitet 15.07.2026 19:18:09
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP requests by supplying a malicious callback URL when...
CVE-2026-58477
- EPSS 0.36%
- Veröffentlicht 14.07.2026 14:39:51
- Zuletzt bearbeitet 14.07.2026 23:17:32
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attacke...
CVE-2026-60114
- EPSS 0.37%
- Veröffentlicht 14.07.2026 14:37:27
- Zuletzt bearbeitet 16.07.2026 18:22:05
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unva...
CVE-2026-58476
- EPSS 0.23%
- Veröffentlicht 14.07.2026 14:25:41
- Zuletzt bearbeitet 14.07.2026 23:17:32
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicio...
CVE-2026-58475
- EPSS 0.21%
- Veröffentlicht 14.07.2026 14:19:19
- Zuletzt bearbeitet 15.07.2026 15:16:45
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitt...