Show filters
97 Total Results
Displaying 1-10 of 97
Sort by:
Attacker Value
Unknown
CVE-2020-24587
Disclosure Date: May 11, 2021 (last updated November 28, 2024)
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
3
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2023-24510
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
1
Attacker Value
Unknown
CVE-2023-24545
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
1
Attacker Value
Unknown
CVE-2024-9188
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Specially constructed queries cause cross platform scripting leaking administrator tokens
0
Attacker Value
Unknown
CVE-2024-9134
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
0
Attacker Value
Unknown
CVE-2024-9133
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
A user with administrator privileges is able to retrieve authentication tokens
0
Attacker Value
Unknown
CVE-2024-9132
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
The administrator is able to configure an insecure captive portal script
0
Attacker Value
Unknown
CVE-2024-9131
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
A user with administrator privileges can perform command injection
0
Attacker Value
Unknown
CVE-2024-7142
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them
0