Vulnerabilities (CVE)

Filtered by vendor Lantronix Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9002 1 Lantronix 1 Xprintserver 2017-09-08 10.0 HIGH N/A
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.
CVE-2014-9003 1 Lantronix 1 Xprintserver 2017-09-08 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for requests that modify configuration, as demonstrated by executing arbitrary commands using the c parameter in the rpc action.
CVE-2007-5981 1 Lantronix 1 Scs3200 2017-07-29 3.3 LOW N/A
Lantronix SCS3200 does not properly handle public-key requests, which allows remote attackers to cause a denial of service (unresponsive device) via unspecified keyscan requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2005-2189 1 Lantronix 1 Securelinx 2016-10-18 5.0 MEDIUM N/A
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.
CVE-2008-7201 1 Lantronix 1 Mss485-t 2009-09-17 7.8 HIGH N/A
Lantronix MSS485-T allows remote attackers to cause a denial of service (unstable performance and service loss) via certain vulnerability scans, as demonstrated using (1) Nessus and (2) nmap.