Vulnerabilities > Getvera > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-23 | CVE-2019-15498 | Argument Injection or Modification vulnerability in Getvera Vera Edge Firmware 1.7.4452 cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh. | 9.3 |
2019-07-14 | CVE-2019-13598 | OS Command Injection vulnerability in Getvera Vera Edge Firmware 1.7.4452 LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped. | 10.0 |
2019-06-17 | CVE-2017-9392 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Getvera Veraedge Firmware and Veralite Firmware An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. | 9.0 |
2019-06-17 | CVE-2017-9391 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Getvera Veraedge Firmware and Veralite Firmware An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. | 9.0 |
2019-06-17 | CVE-2017-9389 | Improper Authentication vulnerability in Getvera Veraedge Firmware and Veralite Firmware An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. | 9.0 |
2019-06-17 | CVE-2017-9384 | Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. | 9.0 |
2019-06-17 | CVE-2017-9388 | Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. | 9.0 |