RelyumCVEs & Vulnerabilities

14 CVEs affecting Relyum products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

rely-pcie 14rely-pcie firmware 14rely-rec 6rely-rec firmware 6
CVE-2024-44577HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

11 Sep 2024
8.8
CVSS
CVE-2024-44575LOW

RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

11 Sep 2024
3.7
CVSS
CVE-2024-44574HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

11 Sep 2024
8.8
CVSS
CVE-2024-44573MEDIUM

A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

11 Sep 2024
4.7
CVSS
CVE-2024-44572HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

11 Sep 2024
8.8
CVSS
CVE-2024-44571HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

11 Sep 2024
8.8
CVSS
CVE-2024-44570HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

11 Sep 2024
8.8
CVSS
CVE-2023-47579HIGH

Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.

13 Dec 2023
7.5
CVSS
CVE-2023-47578HIGH

Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface.

13 Dec 2023
8.8
CVSS
CVE-2023-47577CRITICAL

An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

13 Dec 2023
9.8
CVSS
CVE-2023-47576HIGH

An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

13 Dec 2023
8.8
CVSS
CVE-2023-47575MEDIUM

An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices are susceptible to reflected XSS.

13 Dec 2023
6.1
CVSS
CVE-2023-47574MEDIUM

An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. There is a Weak SMB configuration with signing disabled.

13 Dec 2023
5.9
CVSS
CVE-2023-47573HIGH

An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.

13 Dec 2023
8.8
CVSS
← PrevPage 1 / 1Next →