Page 2 of 16 results (0.006 seconds)

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

27 Mar 2019 — An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged users to create privileged users and execute arbitrary commands via the use of the diagnostic-profile over RESTCONF. Se ha descubierto un problema en ADTRAN PMAA 1.6.2-1, 1.6.3 y 1.6.4. NETCONF Access Management (NACM) permite que los usuarios sin privilegios creen usuarios privilegiados y ejecuten comandos arbitrarios mediante el uso de diagnostic-profile mediante RESTCONF. • https://supportforums.adtran.com/docs/DOC-9344 • CWE-269: Improper Privilege Management •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

19 Sep 2013 — Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Cross-site scripting (XSS) en la página de inicio de sesión de GUI en ADTRAN AOS antes R10.8.1 en el NetVanta 7100, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. Adtran Netvanta 7100 with firmware prior to R10.5.3.HA suffers from bypass, injection... • https://supportforums.adtran.com/docs/DOC-6414 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

29 Dec 2005 — Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. • http://secunia.com/advisories/18179 •

CVSS: 10.0EPSS: 0%CPEs: 3EXPL: 0

29 Dec 2005 — Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via format string specifiers in crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. • http://secunia.com/advisories/18179 •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

29 Dec 2005 — The Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to cause a denial of service via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. • http://secunia.com/advisories/18179 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

19 Apr 2000 — The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash. • http://www.securityfocus.com/bid/1129 •