Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

44723 risultati

VulnerabilitàAlta
CVE-2026-84403 - Botslab G980H Dashcams Missing Authentication for Critical Function

CVE ID :CVE-2026-84403 Published : Sept. 24, 2026, 9:18 p.m. | 3 hours, 50 minutes ago Description :The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range could intercept or directly retrieve sensitive device information, including device identifiers, firmware information, and protected WiFi credentials. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-82716 - Botslab G980H Dashcams Insertion of Sensitive Information into Log File

CVE ID :CVE-2026-82716 Published : Sept. 24, 2026, 9:18 p.m. | 3 hours, 50 minutes ago Description :The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support operation has completed. An unauthenticated attacker with physical access to the storage media could retrieve the logs and obtain sensitive device information. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-81630 - Botslab G980H Dashcams Insufficient Verification of Data Authenticity

CVE ID :CVE-2026-81630 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 11 minutes ago Description :The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware instead of a trusted cryptographic signature. A suitably positioned attacker who intercepts a firmware download, or an authenticated attacker who submits a crafted update, could install modified firmware and execute unauthorized code on the device. Severity: 9.2 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-75558 - Botslab G980H Dashcams Use of Hard-coded Cryptographic Key

CVE ID :CVE-2026-75558 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 11 minutes ago Description :The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic material from the firmware could recover the WiFi password and gain unauthorized access to the device network. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-14443 - Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a

CVE ID :CVE-2026-14443 Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 13 minutes ago Description :Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support archives can obtain these keys, leading to the potential compromise of encrypted network tunnels. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-14441 - Logic flaw in SANnav Java cache key handling object comparison handling

CVE ID :CVE-2026-14441 Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 13 minutes ago Description :A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ensure accurate object evaluation and prevent potential identity mismatch conditions. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-14442 - Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

CVE ID :CVE-2026-14442 Published : Sept. 24, 2026, 9:17 p.m. | 2 hours, 13 minutes ago Description :An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensitive parameters including external server passwords and archive protection keys are logged without proper masking. A local or authenticated user with access to application logs or support bundles can view these cleartext credentials, potentially leading to unauthorized access to remote backup targets or protected archives. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-95699 - MrSteam iSteamX Improper Isolation or Compartmentalization

CVE ID :CVE-2026-95699 Published : Sept. 24, 2026, 9:18 p.m. | 3 hours, 50 minutes ago Description :Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-97368 - chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServiceImpl.userInfo authorization

CVE ID :CVE-2026-97368 Published : Sept. 24, 2026, 9:18 p.m. | 6 hours, 23 minutes ago Description :A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId causes authorization bypass. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. CVE-2026-56100 and CVE-2026-36765 are distinct issues. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-93353 - copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers

CVE ID :CVE-2026-93353 Published : Sept. 24, 2026, 9:18 p.m. | 3 hours, 50 minutes ago Description :copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volflag enforcement. The _mkdir, _rmdir, and _chattr handlers construct destination paths using vfs.get(), vn.canonical(), and os.path.join() without invoking the chk_ap access check, enabling attackers to traverse symlinks leaving a volume's top directory and perform unauthorized file creation, deletion, or truncation via SSH_FXP_SETSTAT operations on paths outside any volume the account is authorized to access. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-82585 - Botslab G980H Dashcams Cleartext Transmission of Sensitive Information

CVE ID :CVE-2026-82585 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 11 minutes ago Description :The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video, location information, images, diagnostic logs, or other sensitive information exchanged between the device and its mobile application. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa
VulnerabilitàAlta
CVE-2026-79959 - Botslab G980H Dashcams Use of Hard-coded Credentials

CVE ID :CVE-2026-79959 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 11 minutes ago Description :The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to obtain root access through the UART interface. Severity: 7.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE6g fa

Pagina 120 di 3727

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.