Meinbergglobal

    Dashboard / Vendors

    Products: 15
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-46902

    An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.

    Last Modified: Jun 17, 2025
    Published: Feb 04, 2024

    CVE-2021-46903

    An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in violation of expected access control).

    Last Modified: Jun 17, 2025
    Published: Feb 04, 2024

    CVE-2023-1731

    Improper Input Validation in Meinberg LTOS

    Last Modified: Feb 04, 2025
    Published: Apr 24, 2023

    CVE-2019-17584

    The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of this device. An update to fix the vulnerability was published by the vendor.

    Last Modified: Nov 21, 2024
    Published: Jan 21, 2020

    CVE-2020-7240

    Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Configuration). Note: According to the description, the vulnerability requires a fully authenticated super-user account using a webUI function that allows super users to edit a script supposed to execute OS commands. The given weakness enumeration (CWE-78) is not applicable in this case as it refers to abusing functions/input fields not supposed to be accepting OS commands by using 'Special Elements.

    Last Modified: Nov 21, 2024
    Published: Jan 20, 2020
    Items Per Page
    Meinbergglobal Vulnerabilities & Security CVEs | CVE-DB