Lucene search

K

Unity Edgeconnect Sd-Wan Firmware Security Vulnerabilities

cve
cve

CVE-2019-16099

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

8.8CVSS

8.5AI Score

0.001EPSS

2019-09-08 05:15 PM
60
cve
cve

CVE-2019-16100

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.

7.5CVSS

7.5AI Score

0.002EPSS

2019-09-08 05:15 PM
63
cve
cve

CVE-2019-16101

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

5.3CVSS

5.3AI Score

0.002EPSS

2019-09-08 05:15 PM
65
cve
cve

CVE-2019-16102

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.

9.8CVSS

9.3AI Score

0.002EPSS

2019-09-08 05:15 PM
77
cve
cve

CVE-2019-16103

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.

7.2CVSS

7.1AI Score

0.001EPSS

2019-09-08 05:15 PM
68
cve
cve

CVE-2019-16104

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

6.1CVSS

6AI Score

0.001EPSS

2019-09-08 05:15 PM
68
cve
cve

CVE-2019-16105

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.

4.9CVSS

5.2AI Score

0.001EPSS

2019-09-08 05:15 PM
64