Vulnerabilities > Digitus

DATE CVE VULNERABILITY TITLE RISK
2022-07-26 CVE-2022-27105 Cross-site Scripting vulnerability in Digitus Inmailx
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS).
network
low complexity
digitus CWE-79
5.4
2020-08-07 CVE-2020-15065 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to denial-of-service the device via long input values.
low complexity
digitus CWE-119
6.5
2020-08-07 CVE-2020-15064 Cross-site Scripting vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
low complexity
digitus CWE-79
4.3
2020-08-07 CVE-2020-15063 Improper Authentication vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
low complexity
digitus CWE-287
8.8
2020-08-07 CVE-2020-15062 Insufficiently Protected Credentials vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
low complexity
digitus CWE-522
8.8