Show filters
236 Total Results
Displaying 1-10 of 236
Sort by:
Attacker Value
Very High

Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode…

Disclosure Date: May 03, 2019 (last updated November 27, 2024)
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user. The vulnerability is due to the presence of a default SSH key pair that is present in all devices. An attacker could exploit this vulnerability by opening an SSH connection via IPv6 to a targeted device using the extracted key materials. An exploit could allow the attacker to access the system with the privileges of the root user. This vulnerability is only exploitable over IPv6; IPv4 is not vulnerable.
Attacker Value
Moderate

CVE-2020-10204

Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Attacker Value
Unknown

CVE-2020-10199

Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Attacker Value
Unknown

CVE-2024-51547

Disclosure Date: February 06, 2025 (last updated February 06, 2025)
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
0
Attacker Value
Unknown

CVE-2024-6784

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0
Attacker Value
Unknown

CVE-2024-6516

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0
Attacker Value
Unknown

CVE-2024-6515

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0
Attacker Value
Unknown

CVE-2024-51555

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
0
Attacker Value
Unknown

CVE-2024-51554

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
0
Attacker Value
Unknown

CVE-2024-51551

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02
0