Show filters
1,998 Total Results
Displaying 201-210 of 1,998
Sort by:
Attacker Value
Unknown
CVE-2024-20265
Disclosure Date: March 27, 2024 (last updated February 26, 2025)
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected device.
This vulnerability exists because unnecessary commands are available during boot time at the physical console. An attacker could exploit this vulnerability by interrupting the boot process and executing specific commands to bypass the Cisco Secure Boot validation checks and load an image that has been tampered with. This image would have been previously downloaded onto the targeted device. A successful exploit could allow the attacker to load the image once. The Cisco Secure Boot functionality is not permanently compromised.
0
Attacker Value
Unknown
CVE-2024-25926
Disclosure Date: March 27, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IndiaNIC Widgets Controller allows Reflected XSS.This issue affects Widgets Controller: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2018-25090
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker can use an XSS attack due to improper neutralization of input during web page generation. User interaction is required. This leads to a limited impact of confidentiality and integrity but no impact of availability.
0
Attacker Value
Unknown
CVE-2015-10123
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.
0
Attacker Value
Unknown
CVE-2024-27121
Disclosure Date: March 12, 2024 (last updated February 26, 2025)
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.
0
Attacker Value
Unknown
CVE-2024-25616
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
0
Attacker Value
Unknown
CVE-2024-25615
Disclosure Date: March 05, 2024 (last updated March 06, 2024)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.
0
Attacker Value
Unknown
CVE-2024-25614
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the integrity of the controller.
0
Attacker Value
Unknown
CVE-2024-25613
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
0
Attacker Value
Unknown
CVE-2024-25612
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
0