Page 13 of 64 results (0.005 seconds)

CVSS: 9.0EPSS: 0%CPEs: 3EXPL: 0

An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version <= 5.08. The SSH restricted shell is available with default credentials. • https://gist.github.com/a05110511t/65d07bc776d7c11b4ccf112a09cca4ab https://github.com/a05110511t/CVE/blob/master/CVE-2020-11733.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. Ivanti Avalanche versión 6.3, permite una inyección SQL que está vagamente asociada con el Servidor Apache HTTP, también se conoce como Bug 683250. • https://forums.ivanti.com/s/article/SQL-Injection-Vulnerability-in-Avalanche • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 • CWE-287: Improper Authentication •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration. Se ha descubierto un problema en Ivanti Avalanche para todas las versiones entre la 5.3 y la 6.2. • https://community.ivanti.com/docs/DOC-68406 •