|
222601
|
5.9 |
MEDIUM
Network
|
arista
|
extensible_operating_system
|
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer …
|
CWE-362
Race Condition
|
CVE-2019-14810
|
2024-11-21 13:27 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222602
|
7.5 |
HIGH
Network
|
zingbox
|
inspector
|
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configuration.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-15023
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222603
|
7.5 |
HIGH
Network
|
zingbox
|
inspector
|
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for the Inspector to be susceptible to ARP spoofing.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-15022
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222604
|
5.3 |
MEDIUM
Network
|
zingbox
|
inspector
|
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easily identify instances of Zingbox Inspectors in a local area network.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-15021
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222605
|
9.8 |
CRITICAL
Network
|
zingbox
|
inspector
|
A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result…
|
CWE-346
Origin Validation Error
|
CVE-2019-15020
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222606
|
9.8 |
CRITICAL
Network
|
zingbox
|
inspector
|
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector.
|
CWE-20
Improper Input Validation
|
CVE-2019-15019
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222607
|
7.5 |
HIGH
Network
|
zingbox
|
inspector
|
A security vulnerability exists in the Zingbox Inspector versions 1.280 and earlier, where authentication is not required when binding the Inspector instance to a different customer tenant.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15018
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222608
|
8.4 |
HIGH
Local
|
zingbox
|
inspector
|
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-15017
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222609
|
8.8 |
HIGH
Network
|
zingbox
|
inspector
|
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from…
|
CWE-89
SQL Injection
|
CVE-2019-15016
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222610
|
8.4 |
HIGH
Local
|
zingbox
|
inspector
|
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining acc…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-15015
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|