Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown
CVE-2022-35412
Disclosure Date: July 08, 2022 (last updated October 07, 2023)
Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the product) to disable some of the agent functionality and then exfiltrate files to an external USB device.
0
Attacker Value
Unknown
CVE-2022-0551
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
0
Attacker Value
Unknown
CVE-2022-0550
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
0
Attacker Value
Unknown
CVE-2021-44273
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or a transparent proxy), with SSL MITM enabled, e2guardian, if built with OpenSSL v1.1.x, did not validate hostnames in certificates of the web servers that it connected to, and thus was itself vulnerable to MITM attacks.
0
Attacker Value
Unknown
CVE-2021-26725
Disclosure Date: February 22, 2021 (last updated February 22, 2025)
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
0
Attacker Value
Unknown
CVE-2021-26724
Disclosure Date: February 22, 2021 (last updated February 22, 2025)
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
0
Attacker Value
Unknown
CVE-2020-7049
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
0
Attacker Value
Unknown
CVE-2020-15307
Disclosure Date: June 30, 2020 (last updated February 21, 2025)
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
0
Attacker Value
Unknown
CVE-2009-4607
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on shell escapes, which allows local users to gain privileges using the "!" character within less to access a privileged shell.
0
Attacker Value
Unknown
CVE-2009-4608
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc. ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to authentication.
0