Vulnerabilities > Gira

DATE CVE VULNERABILITY TITLE RISK
2023-06-30 CVE-2023-33276 Cross-site Scripting vulnerability in Gira KNX IP Router Firmware 3.1.3683.0/3.3.8.0
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist.
network
low complexity
gira CWE-79
6.1
2023-06-29 CVE-2023-33277 Path Traversal vulnerability in Gira KNX IP Router Firmware 3.1.3683.0/3.3.8.0
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.
network
low complexity
gira CWE-22
7.5
2023-05-16 CVE-2023-2739 Cross-site Scripting vulnerability in Gira Home Server Firmware
A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta.
network
low complexity
gira CWE-79
6.1
2020-05-07 CVE-2020-10795 OS Command Injection vulnerability in Gira Tks-Ip-Gateway Firmware 4.0.7.7
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend.
network
low complexity
gira CWE-78
critical
9.0
2020-05-07 CVE-2020-10794 Path Traversal vulnerability in Gira Tks-Ip-Gateway Firmware 4.0.7.7
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database.
network
low complexity
gira CWE-22
5.0