Vulnerabilities > Rangee

DATE CVE VULNERABILITY TITLE RISK
2020-08-20 CVE-2020-16282 OS Command Injection vulnerability in Rangee Rangeeos 8.0.4
In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user.
local
low complexity
rangee CWE-78
8.8
2020-08-20 CVE-2020-16281 Improper Encoding or Escaping of Output vulnerability in Rangee Rangeeos 8.0.4
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restricted environment and execute arbitrary code due to unrestricted context menus being accessible.
local
low complexity
rangee CWE-116
7.8
2020-08-20 CVE-2020-16280 Insufficiently Protected Credentials vulnerability in Rangee Rangeeos 8.0.4
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators.
local
low complexity
rangee CWE-522
5.5
2020-08-20 CVE-2020-16279 OS Command Injection vulnerability in Rangee Rangeeos 8.0.4
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.
network
low complexity
rangee CWE-78
critical
9.8