Vulnerabilities (CVE)

Filtered by vendor Racom Subscribe
Filtered by product M\!dge
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20070 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 3.5 LOW 4.8 MEDIUM
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the virtualization.php dialogs.
CVE-2021-20074 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 9.0 HIGH 8.8 HIGH
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.
CVE-2021-20068 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 3.5 LOW 4.8 MEDIUM
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages.
CVE-2021-20071 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 3.5 LOW 4.8 MEDIUM
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the sms.php dialogs.
CVE-2021-20067 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.
CVE-2021-20072 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 8.7 HIGH 7.2 HIGH
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral.
CVE-2021-20075 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 7.2 HIGH 7.8 HIGH
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.
CVE-2021-20073 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 6.8 MEDIUM 8.8 HIGH
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.
CVE-2021-20069 1 Racom 2 M\!dge, M\!dge Firmware 2023-12-10 3.5 LOW 4.8 MEDIUM
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the regionalSettings.php dialogs.