Show filters
561 Total Results
Displaying 141-150 of 561
Sort by:
Attacker Value
Unknown
CVE-2022-33178
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
A vulnerability in the radius authentication system of Brocade Fabric OS before Brocade Fabric OS 9.0 could allow a remote attacker to execute arbitrary code on the Brocade switch.
0
Attacker Value
Unknown
CVE-2022-28169
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin can create a new user with an admin role using the operator session id. The issue was replicated after intercepting the admin, and operator authorization headers sent unencrypted and editing a user addition request to use the operator's authorization header.
0
Attacker Value
Unknown
CVE-2022-33185
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Several commands in Brocade Fabric OS before Brocade Fabric OS v.9.0.1e, and v9.1.0 use unsafe string functions to process user input. Authenticated local attackers could abuse these vulnerabilities to exploit stack-based buffer overflows, allowing arbitrary code execution as the root user account.
0
Attacker Value
Unknown
CVE-2022-28170
Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
0
Attacker Value
Unknown
CVE-2022-25625
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A malicious unauthorized PAM user can access the administration configuration data and change the values.
0
Attacker Value
Unknown
CVE-2022-37048
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
0
Attacker Value
Unknown
CVE-2022-37049
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
0
Attacker Value
Unknown
CVE-2022-37047
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
0
Attacker Value
Unknown
CVE-2021-27798
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions 7.4.1.x and 7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life published report.
0
Attacker Value
Unknown
CVE-2021-46825
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
0