|
209461
|
6.5 |
MEDIUM
Network
|
infoblox
|
nios
|
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
|
CWE-776
XML Entity Expansion
|
CVE-2020-15303
|
2024-11-21 14:05 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209462
|
7.4 |
HIGH
Network
|
broadcom
|
brocade_sannav fabric_operating_system
|
The host SSH servers of Brocade Fabric OS before Brocade Fabric OS v7.4.2h, v8.2.1c, v8.2.2, v9.0.0, and Brocade SANnav before v2.1.1 utilize keys of less than 2048 bits, which may be vulnerable to m…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-15387
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209463
|
5.3 |
MEDIUM
Network
|
broadcom
|
fabric_operating_system
|
Brocade Fabric OS prior to v9.0.1a and 8.2.3a and after v9.0.0 and 8.2.2d may observe high CPU load during security scanning, which could lead to a slower response to CLI commands and other operation…
|
NVD-CWE-noinfo
|
CVE-2020-15386
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209464
|
5.4 |
MEDIUM
Network
|
broadcom
|
sannav
|
Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and list files without permission. As a result, users without permission can see folders, and hidden files, a…
|
NVD-CWE-noinfo
|
CVE-2020-15385
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209465
|
5.3 |
MEDIUM
Network
|
broadcom
|
sannav
|
Brocade SANNav before version 2.1.1 contains an information disclosure vulnerability. Successful exploitation of internal server information in the initial login response header.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-15384
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209466
|
7.5 |
HIGH
Network
|
broadcom
|
sannav
|
Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-15380
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209467
|
7.5 |
HIGH
Network
|
broadcom
|
brocade_sannav
|
Brocade SANnav before v.2.1.0a could allow remote attackers cause a denial-of-service condition due to a lack of proper validation, of the length of user-supplied data as name for custom field name.
|
CWE-20
Improper Input Validation
|
CVE-2020-15379
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209468
|
5.3 |
MEDIUM
Network
|
broadcom
|
sannav
|
The OVA version of Brocade SANnav before version 2.1.1 installation with IPv6 networking exposes the docker container ports to the network, increasing the potential attack surface.
|
NVD-CWE-noinfo
|
CVE-2020-15378
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209469
|
9.8 |
CRITICAL
Network
|
broadcom
|
sannav
|
Webtools in Brocade SANnav before version 2.1.1 allows unauthenticated users to make requests to arbitrary hosts due to a misconfiguration; this is commonly referred to as Server-Side Request Forgery…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15377
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209470
|
7.5 |
HIGH
Network
|
broadcom
|
fabric_operating_system
|
Running security scans against the SAN switch can cause config and secnotify processes within the firmware before Brocade Fabric OS v9.0.0, v8.2.2d and v8.2.1e to consume all memory leading to denial…
|
NVD-CWE-noinfo
|
CVE-2020-15383
|
2024-11-21 14:05 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|