Show filters
71 Total Results
Displaying 51-60 of 71
Sort by:
Attacker Value
Unknown
CVE-2019-12954
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
0
Attacker Value
Unknown
CVE-2019-17125
Disclosure Date: January 17, 2020 (last updated February 21, 2025)
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
0
Attacker Value
Unknown
CVE-2018-20999
Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
0
Attacker Value
Unknown
CVE-2019-17127
Disclosure Date: April 17, 2019 (last updated February 21, 2025)
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2019-9546
Disclosure Date: March 01, 2019 (last updated November 27, 2024)
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
0
Attacker Value
Unknown
CVE-2019-8917
Disclosure Date: February 18, 2019 (last updated November 27, 2024)
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.
0
Attacker Value
Unknown
CVE-2016-10305
Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
0
Attacker Value
Unknown
CVE-2016-10307
Disclosure Date: March 30, 2017 (last updated November 26, 2024)
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.
0
Attacker Value
Unknown
CVE-2014-9566
Disclosure Date: March 10, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager (IPAM) before 4.3, User Device Tracker (UDT) before 3.2, VoIP & Network Quality Manager (VNQM) before 4.2, Server & Application Manager (SAM) before 6.2, Web Performance Monitor (WPM) before 2.2, and possibly other Solarwinds products, allow remote authenticated users to execute arbitrary SQL commands via the (1) dir or (2) sort parameter to the (a) GetAccounts or (b) GetAccountGroups endpoint.
0
Attacker Value
Unknown
CVE-2013-2822
Disclosure Date: December 21, 2013 (last updated October 05, 2023)
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line.
0