Lucene search

K

SD Security Vulnerabilities

cve
cve

CVE-2023-28558

Memory corruption in WLAN handler while processing PhyID in Tx status...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-09-05 07:15 AM
33
cve
cve

CVE-2023-28564

Memory corruption in WLAN HAL while passing command parameters through WMI...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
30
cve
cve

CVE-2023-28538

Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI...

8.4CVSS

7.8AI Score

0.001EPSS

2023-09-05 07:15 AM
34
cve
cve

CVE-2023-28557

Memory corruption in WLAN HAL while processing command parameters from untrusted WMI...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
27
cve
cve

CVE-2023-28548

Memory corruption in WLAN HAL while processing Tx/Rx commands from...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
26
cve
cve

CVE-2023-28549

Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
30
cve
cve

CVE-2023-28544

Memory corruption in WLAN while sending transmit command from HLOS to UTF...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-09-05 07:15 AM
34
cve
cve

CVE-2023-28559

Memory corruption in WLAN FW while processing command parameters from untrusted WMI...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
28
cve
cve

CVE-2023-28560

Memory corruption in WLAN HAL while processing devIndex from untrusted WMI...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-09-05 07:15 AM
32
cve
cve

CVE-2023-21662

Memory corruption in Core Platform while printing the response buffer in...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-09-05 07:15 AM
35
cve
cve

CVE-2023-21663

Memory Corruption while accessing metadata in...

7.8CVSS

7.6AI Score

0.0004EPSS

2023-09-05 07:15 AM
29
cve
cve

CVE-2023-21655

Memory corruption in Audio while validating and mapping...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-09-05 07:15 AM
28
cve
cve

CVE-2023-21664

Memory Corruption in Core Platform while printing the response buffer in...

7.8CVSS

7.7AI Score

0.0004EPSS

2023-09-05 07:15 AM
31
cve
cve

CVE-2022-33275

Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of...

8.4CVSS

7.7AI Score

0.0004EPSS

2023-09-05 07:15 AM
44
cve
cve

CVE-2022-33220

Information disclosure in Automotive multimedia due to buffer...

5.5CVSS

5.5AI Score

0.0004EPSS

2023-09-05 07:15 AM
35
cve
cve

CVE-2023-37433

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
16
cve
cve

CVE-2023-37436

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

6.5CVSS

6.7AI Score

0.001EPSS

2023-08-22 07:16 PM
19
cve
cve

CVE-2023-37437

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

6.5CVSS

6.7AI Score

0.001EPSS

2023-08-22 07:16 PM
22
cve
cve

CVE-2023-37432

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
7
cve
cve

CVE-2023-37438

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

6.5CVSS

6.7AI Score

0.001EPSS

2023-08-22 07:16 PM
10
cve
cve

CVE-2023-37434

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
18
cve
cve

CVE-2023-37440

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the...

5.5CVSS

5.1AI Score

0.001EPSS

2023-08-22 07:16 PM
9
cve
cve

CVE-2023-37435

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

6.5CVSS

6.7AI Score

0.001EPSS

2023-08-22 07:16 PM
11
cve
cve

CVE-2023-37439

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

6.1CVSS

6.5AI Score

0.001EPSS

2023-08-22 07:16 PM
9
cve
cve

CVE-2023-37431

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
20
cve
cve

CVE-2023-37430

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
12
cve
cve

CVE-2023-37427

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on...

7.2CVSS

7.3AI Score

0.001EPSS

2023-08-22 07:16 PM
11
cve
cve

CVE-2023-37428

A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to....

7.2CVSS

7AI Score

0.001EPSS

2023-08-22 07:16 PM
14
cve
cve

CVE-2023-37425

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute...

8CVSS

6.1AI Score

0.001EPSS

2023-08-22 07:16 PM
16
cve
cve

CVE-2023-37426

EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator...

7.5CVSS

7.4AI Score

0.0005EPSS

2023-08-22 07:16 PM
7
cve
cve

CVE-2023-37429

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and...

8.1CVSS

8.1AI Score

0.001EPSS

2023-08-22 07:16 PM
15
cve
cve

CVE-2023-37421

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute...

8.1CVSS

5.5AI Score

0.0005EPSS

2023-08-22 07:16 PM
18
cve
cve

CVE-2023-37422

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute...

8.1CVSS

5.5AI Score

0.0005EPSS

2023-08-22 07:16 PM
16
cve
cve

CVE-2023-37423

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute...

8.1CVSS

5.5AI Score

0.0005EPSS

2023-08-22 07:16 PM
8
cve
cve

CVE-2023-37424

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability....

8.1CVSS

8.2AI Score

0.001EPSS

2023-08-22 07:16 PM
10
cve
cve

CVE-2023-28537

Memory corruption while allocating memory in COmxApeDec module in...

8.4CVSS

7.8AI Score

0.0004EPSS

2023-08-08 10:15 AM
53
cve
cve

CVE-2023-21626

Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one...

7.1CVSS

7AI Score

0.0004EPSS

2023-08-08 10:15 AM
50
cve
cve

CVE-2023-21652

Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after...

7.7CVSS

6.7AI Score

0.0004EPSS

2023-08-08 10:15 AM
44
cve
cve

CVE-2023-21651

Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in...

9.3CVSS

7.5AI Score

0.0004EPSS

2023-08-08 10:15 AM
42
cve
cve

CVE-2023-22666

Memory Corruption in Audio while playing amrwbplus clips with modified...

8.4CVSS

7.6AI Score

0.0004EPSS

2023-08-08 10:15 AM
42
cve
cve

CVE-2023-21647

Information disclosure in Bluetooth when an GATT packet is received due to improper input...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-08-08 10:15 AM
35
cve
cve

CVE-2023-21627

Memory corruption in Trusted Execution Environment while calling service API with invalid...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-08-08 10:15 AM
33
cve
cve

CVE-2022-40510

Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS...

9.8CVSS

9.6AI Score

0.001EPSS

2023-08-08 10:15 AM
54
cve
cve

CVE-2020-26065

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP...

6.5CVSS

6.2AI Score

0.001EPSS

2023-08-04 09:15 PM
33
cve
cve

CVE-2020-26064

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain...

8.1CVSS

7.9AI Score

0.001EPSS

2023-08-04 09:15 PM
30
cve
cve

CVE-2023-20214

A vulnerability in the request authentication validation for the REST API of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to gain read permissions or limited write permissions to the configuration of an affected Cisco SD-WAN vManage instance. This vulnerability is.....

9.1CVSS

9.3AI Score

0.001EPSS

2023-08-03 10:15 PM
2705
cve
cve

CVE-2023-20899

VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN...

7.5CVSS

7.7AI Score

0.003EPSS

2023-07-06 11:15 PM
19
cve
cve

CVE-2023-35977

Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing...

6.5CVSS

6.3AI Score

0.001EPSS

2023-07-05 03:15 PM
13
cve
cve

CVE-2023-35978

A vulnerability in ArubaOS could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in...

6.1CVSS

6.2AI Score

0.001EPSS

2023-07-05 03:15 PM
13
cve
cve

CVE-2023-35972

An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully....

7.2CVSS

7.4AI Score

0.001EPSS

2023-07-05 03:15 PM
12
Total number of security vulnerabilities1467