Showing 4 vulnerabilities on this page for utnserver_pro

Signals CISA KEV Ransomware Nuclei
seh vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Multiple Stored Cross-Site Scripting

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CWE-79Nov 18, 2024
CVSS5.1v4.0EPSS0.535%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Denial of Service

An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CWE-400Jun 4, 2024
CVSS7.1v4.0EPSS0.665%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Authenticated Command Injection

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CWE-78Jun 4, 20241 related artifact
CVSS8.7v4.0EPSS3.69%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Stored Cross-Site Scripting in SEH Computertechnik utnserver Pro

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

CWE-79Jun 4, 20241 related artifact
CVSS8.3v4.0EPSS5.5%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX