Home/Product/relyum rely pcie firmware
Product

relyum rely pcie firmware

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-44577
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
8.8HIGH
CVE-2024-44575
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user
3.7LOW
CVE-2024-44574
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
8.8HIGH
CVE-2024-44573
>= 22.2.1 and <= 23.1.0
A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to ex
4.7MEDIUM
CVE-2024-44572
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
8.8HIGH
CVE-2024-44571
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
8.8HIGH
CVE-2024-44570
>= 22.2.1 and <= 23.1.0
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.
8.8HIGH
CVE-2023-47579
all versions
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash fil
7.5HIGH
CVE-2023-47578
all versions
Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absenc
8.8HIGH
CVE-2023-47577
all versions
An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for cu
9.8CRITICAL
CVE-2023-47576
all versions
An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through t
8.8HIGH
CVE-2023-47575
all versions
An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices are susce
6.1MEDIUM
CVE-2023-47574
all versions
An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. There is a Weak SMB configuration with signing dis
5.9MEDIUM
CVE-2023-47573
all versions
An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing
8.8HIGH
threatengine.sh