[FD] Circontrol EV Charger vulnerabilities (CVE-2020-8006, CVE-2020-8007)

2024-03-27 Thread Dariusz G
Circontrol EV Charger vulnerabilities. 1. CVE-2020-8006 Pre-Auth Stack Based Buffer Overflow CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10) The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the

[FD] Novus Managment System Vulnerabilities (CVE-2021-34820, CVE-2021-38421)

2021-07-09 Thread Dariusz G
Hello, Vulnerabilities mentioned below are fixed in the NMS with 1.51.2 version. Vendor has already published the patches. Please visit https://nms.aat.pl/en/ to download patches for the NMS software. I believe that all NMS software with version below 1.51.2 is affected by Web Path Traversal and C