Show filters
376 Total Results
Displaying 71-80 of 376
Sort by:
Attacker Value
Unknown

CVE-2023-30243

Disclosure Date: May 05, 2023 (last updated October 08, 2023)
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
Attacker Value
Unknown

CVE-2023-30242

Disclosure Date: May 05, 2023 (last updated October 08, 2023)
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
Attacker Value
Unknown

CVE-2023-29163

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-28406

Disclosure Date: May 03, 2023 (last updated October 09, 2023)
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-27378

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-24594

Disclosure Date: May 03, 2023 (last updated October 09, 2023)
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2019-18177

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
Attacker Value
Unknown

CVE-2022-27510

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
Unauthorized access to Gateway user capabilities
Attacker Value
Unknown

CVE-2022-27513

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
Remote desktop takeover via phishing
Attacker Value
Unknown

CVE-2022-27516

Disclosure Date: November 08, 2022 (last updated October 19, 2023)
User login brute force protection functionality bypass