|
197631
|
8.8 |
HIGH
Network
|
dell
|
emc_isilon_onefs emc_powerscale_onefs
|
Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with network or local file access, could take advantage o…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-5371
|
2024-11-21 14:34 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197632
|
7.5 |
HIGH
Network
|
dell
|
vxrail_d560f_firmware vxrail_d560_firmware
|
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an e…
|
CWE-862
Missing Authorization
|
CVE-2020-5368
|
2024-11-21 14:34 |
2020-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197633
|
7.3 |
HIGH
Network
|
f5
|
nginx_controller
|
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.
|
NVD-CWE-noinfo
|
CVE-2020-5911
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197634
|
7.5 |
HIGH
Network
|
f5
|
nginx_controller
|
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any succe…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-5910
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197635
|
5.4 |
MEDIUM
Network
|
f5
|
nginx_controller
|
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-5909
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197636
|
5.5 |
MEDIUM
Local
|
f5
|
big-ip_access_policy_manager
|
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-5908
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197637
|
7.2 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access only to the TMOS Shell (tmsh) may be able to conduc…
|
NVD-CWE-noinfo
|
CVE-2020-5907
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197638
|
8.1 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin us…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-5906
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197639
|
9.6 |
CRITICAL
Network
|
f5
|
nginx_controller
|
In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compro…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5901
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197640
|
7.8 |
HIGH
Local
|
f5
|
nginx_controller
|
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database co…
|
CWE-312 CWE-319 CWE-522
Cleartext Storage of Sensitive Information Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-5899
|
2024-11-21 14:34 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|