|
199431
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "uplo…
|
CWE-78
OS Command
|
CVE-2020-29381
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199432
|
5.9 |
MEDIUM
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-29380
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199433
|
5.5 |
MEDIUM
Local
|
vsolcn
|
v1600d4l_firmware v1600d-mini_firmware
|
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does n…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29379
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199434
|
8.8 |
HIGH
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privil…
|
CWE-287
Improper Authentication
|
CVE-2020-29378
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199435
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29377
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199436
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. There is an !j@l#y$z%x6x7q8c9z) pass…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29376
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199437
|
8.8 |
HIGH
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. An low-privileged (non-admin) attack…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29375
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199438
|
6.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintend…
|
CWE-22
Path Traversal
|
CVE-2020-29373
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199439
|
4.7 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1…
|
CWE-362
Race Condition
|
CVE-2020-29372
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199440
|
3.6 |
LOW
Local
|
linux debian netapp
|
linux_kernel debian_linux 500f_firmware a250_firmware h410c_firmware solidfire_\&_hci_management_node hci_compute_node_bios solidfire_\&_hci_storage_node
|
An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly …
|
CWE-362 CWE-863
Race Condition Incorrect Authorization
|
CVE-2020-29374
|
2024-11-21 14:23 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|