Vulnerabilities > Getvera > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-15498 Argument Injection or Modification vulnerability in Getvera Vera Edge Firmware 1.7.4452
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.
network
getvera CWE-88
critical
9.3
2019-07-14 CVE-2019-13598 OS Command Injection vulnerability in Getvera Vera Edge Firmware 1.7.4452
LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.
network
low complexity
getvera CWE-78
critical
10.0
2019-06-17 CVE-2017-9392 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-119
critical
9.0
2019-06-17 CVE-2017-9391 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-119
critical
9.0
2019-06-17 CVE-2017-9389 Improper Authentication vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-287
critical
9.0
2019-06-17 CVE-2017-9384 Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-77
critical
9.0
2019-06-17 CVE-2017-9388 Command Injection vulnerability in Getvera Veraedge Firmware and Veralite Firmware
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices.
network
low complexity
getvera CWE-77
critical
9.0