Show filters
561 Total Results
Displaying 31-40 of 561
Sort by:
Attacker Value
Unknown

CVE-2024-36457

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
0
Attacker Value
Unknown

CVE-2024-36456

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown

CVE-2024-36455

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2024-3596

Disclosure Date: July 09, 2024 (last updated January 07, 2025)
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Attacker Value
Unknown

CVE-2024-5460

Disclosure Date: June 26, 2024 (last updated February 05, 2025)
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to hard-coded, default community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 1 queries to an affected device.
Attacker Value
Unknown

CVE-2024-29954

Disclosure Date: June 26, 2024 (last updated August 07, 2024)
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp. Detail. When the firmwaredownload command is incorrectly entered or points to an erroneous file, the firmware download log captures the failed command, including any password entered in the command line.
Attacker Value
Unknown

CVE-2024-29953

Disclosure Date: June 26, 2024 (last updated February 05, 2025)
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Attacker Value
Unknown

CVE-2024-36459

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
0
Attacker Value
Unknown

CVE-2024-2860

Disclosure Date: May 08, 2024 (last updated February 07, 2025)
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
Attacker Value
Unknown

CVE-2024-4173

Disclosure Date: April 25, 2024 (last updated February 07, 2025)
A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.