Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown

CVE-2021-41300

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
0
Attacker Value
Unknown

CVE-2021-41301

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
0
Attacker Value
Unknown

CVE-2021-41298

Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
0
Attacker Value
Unknown

CVE-2016-6594

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
0
Attacker Value
Unknown

CVE-2016-10259

Disclosure Date: April 11, 2017 (last updated November 26, 2024)
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.
0
Attacker Value
Unknown

CVE-2016-9091

Disclosure Date: April 05, 2017 (last updated November 26, 2024)
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.
0
Attacker Value
Unknown

CVE-2015-8597

Disclosure Date: January 08, 2016 (last updated November 25, 2024)
Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."
0
Attacker Value
Unknown

CVE-2015-8482

Disclosure Date: December 07, 2015 (last updated October 05, 2023)
Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enforcement mode, which allows local administrators to unblock categories or disable the agent via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-1454

Disclosure Date: February 02, 2015 (last updated October 05, 2023)
Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7135

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Ayuntamiento de Coana (aka com.wInfoCoa) application 0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0