Vulnerabilities > Proges > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-31 CVE-2024-31202 Incorrect Permission Assignment for Critical Resource vulnerability in Proges Thermoscan IP 20211103
A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.
local
low complexity
proges CWE-732
7.8
2024-07-31 CVE-2024-3083 Cross-Site Request Forgery (CSRF) vulnerability in Proges Sensor NET Connect Firmware V2 2.24
A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting a malicious web page.
network
low complexity
proges CWE-352
8.3