CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.
Intesync Solismed 3.3sp allows Insecure File Upload.
Intesync Solismed 3.3sp has XSS.
Intesync Solismed 3.3sp has CSRF.
Intesync Solismed 3.3sp has SQL Injection.
Intesync Solismed 3.3sp has Incorrect Access Control.
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
Intesync Solismed 3.3sp allows Clickjacking.
Sd-wan_firmware, Vedge-100, Vedge-1000, Vedge-100b, Vedge-2000, Vedge-5000, Vedge_100m, Vedge_100wm, Hyperflex_hx220c_m5_firmware, Hyperflex_hx220c_m5
2020-10-08
N/A
7.8 HIGH
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the incorrect implementation of a Bash shell command that allows role-based access control (RBAC) to be bypassed. An attacker could exploit this vulnerability by authenticating to the device and entering a crafted command at the Bash prompt. A successful exploit could allow the attacker to escalate their privilege level by executing commands that should be restricted to other roles. For example, a dev-ops user could escalate their privilege level to admin with a successful exploit of this vulnerability.
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
