HGiga Vulnerabilities and Affected Products
Vulnerabilities associated with PowerStation.
Products
Clear product- iSherlock 4.59 vulnerabilities
- iSherlock 5.59 vulnerabilities
- MailSherlock MSR45/SSR458 vulnerabilities
- isherlock6 vulnerabilities
- MailSherlock4 vulnerabilities
- OAKlouds4 vulnerabilities
- PowerStation3 vulnerabilities
- C&Cm@il package olln-base2 vulnerabilities
- C&Cmail2 vulnerabilities
- OAKlouds OAKSv22 vulnerabilities
- OAKlouds OAKSv32 vulnerabilities
- C&Cm@il1 vulnerability
- C&Cm@il package olln-base1 vulnerability
- iSherlock-audit-4.51 vulnerability
- iSherlock-audit-5.51 vulnerability
- iSherlock-base-4.51 vulnerability
- iSherlock-base-5.51 vulnerability
- iSherlock-maillog-4.51 vulnerability
- iSherlock-maillog-5.51 vulnerability
- iSherlock-smtp-4.51 vulnerability
- iSherlock-smtp-5.51 vulnerability
- oaklouds-organization1 vulnerability
- oaklouds-webbase1 vulnerability
- OAKSv20 OAKlouds-document_v31 vulnerability
- OAKSv20 OAKlouds-document_v3 2.01 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3364MEDIUM | HGiga PowerStation - Chroot EscapeThe SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers with root privileges to bypass chroot restrictions and access the entire file system. CWE-250Apr 8, 2025 | CVSS6.7v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24838CRITICAL | HGiga PowerStation - Information LeakageHGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution. | CVSS9.8v3.1 | EPSS1.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24837HIGH | HGiga PowerStation - Command InjectionHGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service. CWE-78Mar 27, 2023 | CVSS8.8v3.1 | EPSS0.933% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |