VendorsLoftwarespectrumany version
Vulnerabilities

Loftware Spectrum any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-37227
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
Published 2024-09-10 · Analyzed
9.8EPSS 0.006
CVE-2023-37226
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
Published 2024-09-10 · Analyzed
9.8EPSS 0.006
CVE-2023-37231
Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.
Published 2024-09-10 · Analyzed
9.8EPSS 0.005
CVE-2023-37234
Loftware Spectrum through 4.6 has unprotected JMX Registry.
Published 2024-09-10 · Analyzed
9.8EPSS 0.004
CVE-2023-37233
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
Published 2024-09-10 · Analyzed
8.8EPSS 0.004
CVE-2023-37229
Loftware Spectrum before 5.1 allows SSRF.
Published 2024-09-10 · Analyzed
8.8EPSS 0.004
CVE-2023-37230
Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.
Published 2024-09-10 · Analyzed
8.8EPSS 0.004
CVE-2023-37232
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
Published 2024-09-10 · Analyzed
7.5EPSS 0.004