Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown
CVE-2017-5255
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly user) to inject shell meta-characters as part of a specially-crafted POST request to the get_chart function and run OS-level commands, effectively as root.
0
Attacker Value
Unknown
CVE-2017-7922
Disclosure Date: June 21, 2017 (last updated November 26, 2024)
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration changes.
0
Attacker Value
Unknown
CVE-2017-7918
Disclosure Date: June 21, 2017 (last updated November 26, 2024)
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access control and may allow access to sensitive information and possibly allow for configuration changes.
0
Attacker Value
Unknown
CVE-2017-7938
Disclosure Date: April 20, 2017 (last updated April 30, 2024)
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.
0
Attacker Value
Unknown
CVE-2013-3584
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Corporater EPM Suite allows remote attackers to inject arbitrary web script or HTML via the customerId parameter to an unspecified component.
0
Attacker Value
Unknown
CVE-2013-3583
Disclosure Date: August 28, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in saveProperties.html in Corporater EPM Suite allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.
0