|
223251
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arb…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12119
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223252
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arb…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12118
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223253
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may exec…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12117
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223254
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitra…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12116
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223255
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitra…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12115
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223256
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execut…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-12114
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223257
|
8.8 |
HIGH
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include adm…
|
CWE-78
OS Command
|
CVE-2019-12113
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223258
|
9.8 |
CRITICAL
Network
|
onap
|
open_network_automation_platform
|
An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that includ…
|
CWE-78
OS Command
|
CVE-2019-12112
|
2024-11-21 13:22 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223259
|
7.5 |
HIGH
Network
|
facebook
|
thrift
|
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would resu…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-11939
|
2024-11-21 13:22 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223260
|
9.8 |
CRITICAL
Network
|
safescan
|
ta-8010_firmware ta-8015_firmware ta-8020_firmware ta-8025_firmware ta-8030_firmware ta-8035_firmware tm-616_firmware
|
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
|
CWE-22
Path Traversal
|
CVE-2019-12182
|
2024-11-21 13:22 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|