GiraCVEs & Vulnerabilities

5 CVEs affecting Gira products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

knx ip router firmware 4knx ip router 2tks-ip-gateway 2tks-ip-gateway firmware 2gira home server 1gira home server firmware 1
CVE-2023-33276MEDIUM

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding, it is vulnerable to reflective cross-site scripting (XSS).

30 Jun 2023
6.1
CVSS
CVE-2023-33277HIGH

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.

29 Jun 2023
7.5
CVSS
CVE-2023-2739MEDIUM

A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affects unknown code of the file /hslist. The manipulation of the argument lst with the input debug%27"><img%20src=x%20onerror=alert(document.cookie)> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-229150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

16 May 2023
6.1
CVSS
CVE-2020-10795HIGH

Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remote root access.

8 May 2020
7.2
CVSS
CVE-2020-10794CRITICAL

Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.

8 May 2020
9.8
CVSS
← PrevPage 1 / 1Next →
Gira CVEs & Vulnerabilities — 5 Tracked