Show filters
561 Total Results
Displaying 31-40 of 561
Sort by:
Attacker Value
Unknown
CVE-2024-36457
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.
0
Attacker Value
Unknown
CVE-2024-36456
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
0
Attacker Value
Unknown
CVE-2024-36455
Disclosure Date: July 15, 2024 (last updated July 16, 2024)
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2024-3596
Disclosure Date: July 09, 2024 (last updated January 07, 2025)
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
0
Attacker Value
Unknown
CVE-2024-5460
Disclosure Date: June 26, 2024 (last updated February 05, 2025)
A vulnerability in the default configuration of the Simple Network
Management Protocol (SNMP) feature of Brocade Fabric OS versions before
v9.0.0 could allow an authenticated, remote attacker to read data from
an affected device via SNMP. The vulnerability is due to hard-coded,
default community string in the configuration file for the SNMP daemon.
An attacker could exploit this vulnerability by using the static
community string in SNMP version 1 queries to an affected device.
0
Attacker Value
Unknown
CVE-2024-29954
Disclosure Date: June 26, 2024 (last updated August 07, 2024)
A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information in log files. This could allow an authenticated user to view the server passwords for protocols such as scp and sftp.
Detail.
When the firmwaredownload command is incorrectly entered or points to an erroneous file, the firmware download log captures the failed command, including any password entered in the command line.
0
Attacker Value
Unknown
CVE-2024-29953
Disclosure Date: June 26, 2024 (last updated February 05, 2025)
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms.
This could allow an authenticated user to view other users' session encoded passwords.
0
Attacker Value
Unknown
CVE-2024-36459
Disclosure Date: June 14, 2024 (last updated June 15, 2024)
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
0
Attacker Value
Unknown
CVE-2024-2860
Disclosure Date: May 08, 2024 (last updated February 07, 2025)
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.
0
Attacker Value
Unknown
CVE-2024-4173
Disclosure Date: April 25, 2024 (last updated February 07, 2025)
A vulnerability in Brocade SANnav exposes Kafka in the wan interface.
The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against the Brocade SANnav.
0