Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-42425: CVE-2023-42425 Details

An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.

CVE
#vulnerability#ssl

Description

An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.

Vulnerability Type

Missing SSL Certificate Validation

Vendor of Product

Turing Video

Affected Product Code Base

Turing Edge+ EVC5FD - Firmware version: 1.38.6

Attack Type

Remote

Impact Information Disclosure

True

Has vendor confirmed or acknowledged the vulnerability?

True

Discoverer

IPVM

Workaround

Firware version 1.40.1 onwards includes fix for this vulnerability.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907