[FD] SEC Consult SA-20250611-0 :: Undocumented Root Shell Access on SIMCom SIM7600G Modem

2025-06-17 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250611-0 > === title: Undocumented Root Shell Access product: SIMCom - SIM7600G Modem vulnerable version: Firmware Revision: LE20B03SIM7600M21-A

[FD] SEC Consult SA-20250521-0 :: Multiple Vulnerabilities in eCharge Hardy Barth cPH2 and cPP2 charging stations

2025-05-27 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250521-0 > === title: Multiple Vulnerabilities product: eCharge Hardy Barth cPH2 and cPP2 charging stations vulnerable version: 2.2.0 fixed versi

[FD] SEC Consult SA-20250506-0 :: Honeywell MB Secure Authenticated Command Injection

2025-05-16 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250507-0 > === title: Authenticated Command Injection product: Honeywell MB-Secure vulnerable version: MB-Secure versions from V11.04 and prior to V12.5

[FD] SEC Consult SA-20250422-0:: Local Privilege Escalation via DLL Search Order Hijacking

2025-05-16 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250422-0 > === title: Local Privilege Escalation via DLL Search Order Hijacking product: Ivanti Endpoint Manager Security Scan (Vulscan) Self Update vu

[FD] SEC Consult SA-20250429-0 :: Multiple Vulnerabilities in HP Wolf Security Controller and more

2025-05-16 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < publishing date 20250429-0 > Combined Security Advisory for Sure Access Enterprise and Sure Click Enterprise === title: Multiple Vulnerabilities product:

[FD] SEC Consult SA-20250226-0 :: Multiple vulnerabilities in Siemens A8000 CP-8050 & CP-8031 PLC

2025-02-27 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250226-0 > === title: Multiple Vulnerabilities product: Siemens A8000 CP-8050 PLC Siemens A8000 CP-8031 PLC vulnerable version: <0

[FD] SEC Consult SA-20250127-0 :: Weak Password Hashing Algorithms in Wind River Software VxWorks RTOS

2025-01-27 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20250127-0 > === title: Weak Password Hashing Algorithms product: Wind River Software VxWorks RTOS vulnerable version: >= VxWorks 6.9 fixed ver

[FD] SEC Consult SA-20240418-0 :: Broken authorization in Dreamehome app

2024-04-19 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20240418-0 > === title: Broken authorization product: Dreamehome app vulnerable version: <=2.1.5 (iOS) fixed version: none, see solution

[FD] SEC Consult SA-20240411-0 :: Database Passwords in Server Response in Amazon AWS Glue

2024-04-14 Thread SEC Consult Vulnerability Lab via Fulldisclosure
SEC Consult Vulnerability Lab Security Advisory < 20240411-0 > === title: Database Passwords in Server Response product: Amazon AWS Glue vulnerable version: until 2024-02-23 fixed version: as of