Vulnerabilities > Cellinx

DATE CVE VULNERABILITY TITLE RISK
2024-02-08 CVE-2024-24215 Unspecified vulnerability in Cellinx NVT web Server 5.0.0.014
An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.
network
low complexity
cellinx
5.3
2023-02-22 CVE-2023-23063 Path Traversal vulnerability in Cellinx NVT web Server 1.0.6.002B
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
network
low complexity
cellinx CWE-22
7.5
2022-07-18 CVE-2022-30620 Reliance on Cookies without Validation and Integrity Checking vulnerability in Cellinx NVT - IP PTZ Camera Firmware 3.2.0/3.2.1
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig".
network
low complexity
cellinx CWE-565
8.8
2022-07-18 CVE-2022-30621 Use of Incorrectly-Resolved Name or Reference vulnerability in Cellinx NVT - IP PTZ Camera Firmware 3.2.0/3.2.1
Allows a remote user to read files on the camera's OS "GetFileContent.cgi".
network
low complexity
cellinx CWE-706
6.5
2020-11-06 CVE-2020-28250 Unspecified vulnerability in Cellinx NVT web Server 5.0.0.014B
Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi because authentication is on the client side.
network
low complexity
cellinx
critical
9.8