Show filters
124 Total Results
Displaying 11-20 of 124
Sort by:
Attacker Value
Unknown

CVE-2025-23052

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
0
Attacker Value
Unknown

CVE-2025-23051

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
0
Attacker Value
Unknown

CVE-2024-54007

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
0
Attacker Value
Unknown

CVE-2024-54006

Disclosure Date: January 07, 2025 (last updated January 08, 2025)
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
0
Attacker Value
Unknown

CVE-2024-54008

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
0
Attacker Value
Unknown

CVE-2024-53672

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-51773

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.
0
Attacker Value
Unknown

CVE-2024-51772

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-51771

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
0
Attacker Value
Unknown

CVE-2024-47464

Disclosure Date: November 05, 2024 (last updated November 06, 2024)
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.
0