Show filters
236 Total Results
Displaying 1-10 of 236
Sort by:
Attacker Value
Very High
Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode…
Disclosure Date: May 03, 2019 (last updated November 27, 2024)
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user. The vulnerability is due to the presence of a default SSH key pair that is present in all devices. An attacker could exploit this vulnerability by opening an SSH connection via IPv6 to a targeted device using the extracted key materials. An exploit could allow the attacker to access the system with the privileges of the root user. This vulnerability is only exploitable over IPv6; IPv4 is not vulnerable.
0
Attacker Value
Moderate
CVE-2020-10204
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
0
Attacker Value
Unknown
CVE-2020-10199
Disclosure Date: April 01, 2020 (last updated November 27, 2024)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2024-51547
Disclosure Date: February 06, 2025 (last updated February 06, 2025)
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
0
Attacker Value
Unknown
CVE-2024-6784
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
0
Attacker Value
Unknown
CVE-2024-6516
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
0
Attacker Value
Unknown
CVE-2024-6515
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
0
Attacker Value
Unknown
CVE-2024-51555
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
0
Attacker Value
Unknown
CVE-2024-51554
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02
0
Attacker Value
Unknown
CVE-2024-51551
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.
Affected products:
ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02
0