Show filters
732 Total Results
Displaying 91-100 of 732
Sort by:
Attacker Value
Unknown

CVE-2024-26297

Disclosure Date: February 27, 2024 (last updated February 28, 2024)
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown

CVE-2024-26296

Disclosure Date: February 27, 2024 (last updated February 28, 2024)
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown

CVE-2024-26295

Disclosure Date: February 27, 2024 (last updated February 28, 2024)
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown

CVE-2024-26294

Disclosure Date: February 27, 2024 (last updated February 28, 2024)
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
0
Attacker Value
Unknown

CVE-2023-47131

Disclosure Date: February 08, 2024 (last updated February 16, 2024)
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
Attacker Value
Unknown

CVE-2023-48383

Disclosure Date: January 15, 2024 (last updated January 23, 2024)
NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Attacker Value
Unknown

CVE-2023-49949

Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.
Attacker Value
Unknown

CVE-2023-51772

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click on the Help icon, observe that there is a browser window for the One Identity website, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.
Attacker Value
Unknown

CVE-2023-48654

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA section, click on the Privacy link, observe that there is a new browser window, navigate to any website that offers file upload, navigate to cmd.exe from the file explorer window, and launch cmd.exe as NT AUTHORITY\SYSTEM.
Attacker Value
Unknown

CVE-2023-49032

Disclosure Date: December 21, 2023 (last updated January 03, 2024)
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.