riverbed records
17 published records for vendor riverbed.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-521 Weak Password Requirements2
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-42786No exploit | Remote Code Execution at AgentControllerServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Critical9.8 | — | 2.1% | Mar 10, 2022 |
39Monitor | CVE-2021-42853No exploit | Directory Traversal Delete/Read at AgentDiagnosticServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Critical9.8 | — | 1.6% | Mar 10, 2022 |
39Monitor | CVE-2021-42854No exploit | Directory Traversal Read/Write/Delete at PluginServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Critical9.8 | — | 1.6% | Mar 10, 2022 |
39Monitor | CVE-2021-42787No exploit | Directory Traversal Write/Delete/Partial Read at AgentConfigurationServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Critical9.8 | — | 1.3% | Mar 10, 2022 |
32Monitor | CVE-2019-3800No exploit | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | High7.8 | — | 2.1% | Aug 5, 2019 |
31Monitor | CVE-2020-15592No exploit | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file.riverbed · steelcentral aternity agent · CWE-22 | High7.5 | — | 1.9% | Jul 27, 2020 |
31Monitor | CVE-2020-15593No exploit | SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC.riverbed · steelcentral aternity agent | High7.8 | — | 0.4% | Jul 27, 2020 |
31Monitor | CVE-2021-42855No exploit | Local privilege escalation due to misconfigured write permission on .debug_command.config fileriverbed · steelcentral appinternals dynamic sampling agent · CWE-284 | High7.8 | — | 0.2% | Mar 10, 2022 |
27Monitor | CVE-2017-7693No exploit | Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated riverbed · opnet app response xpert · CWE-22 | Medium6.5 | — | 3.9% | Aug 26, 2017 |
27Monitor | CVE-2021-43271No exploit | Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when coriverbed · appresponse · CWE-532 | Medium6.8 | — | 0.8% | Jun 3, 2022 |
27Monitor | CVE-2017-7307No exploit | Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attacriverbed · rios · CWE-732 | Medium6.8 | — | 0.3% | Apr 4, 2017 |
25Monitor | CVE-2017-7306No exploit | Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to deriverbed · rios · CWE-521 | Medium6.4 | — | 0.4% | Apr 4, 2017 |
24Monitor | CVE-2021-42856No exploit | Reflected Cross-site Scripting at DsaDataTestriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Medium6.1 | — | 0.6% | Mar 10, 2022 |
21Monitor | CVE-2021-42857No exploit | Directory Traversal Partial Write at AgentDaServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Medium5.3 | — | 1.2% | Mar 10, 2022 |
18Monitor | CVE-2017-5670No exploit | Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate riverbed · rios · CWE-200 | Medium4.6 | — | 0.4% | Apr 4, 2017 |
18Monitor | CVE-2017-7305No exploit | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the sriverbed · rios · CWE-521 | Medium4.6 | — | 0.3% | Apr 4, 2017 |
17Monitor | CVE-2014-5348No exploit | Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6riverbed · steelapp traffic manager · CWE-79 | Medium4.3 | — | 1.4% | Aug 19, 2014 |
- CVE-2021-4278640Plan
Remote Code Execution at AgentControllerServlet
CriticalCVSS 9.8No exploitEPSS 2%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2021-4285339Monitor
Directory Traversal Delete/Read at AgentDiagnosticServlet
CriticalCVSS 9.8No exploitEPSS 2%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2021-4285439Monitor
Directory Traversal Read/Write/Delete at PluginServlet
CriticalCVSS 9.8No exploitEPSS 2%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2021-4278739Monitor
Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet
CriticalCVSS 9.8No exploitEPSS 1%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2019-380032Monitor
CF CLI writes the client id and secret to config file
HighCVSS 7.8No exploitEPSS 2%pivotal · cloud foundry command line interfaceAug 5, 2019
- CVE-2020-1559231Monitor
SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file.
HighCVSS 7.5No exploitEPSS 2%riverbed · steelcentral aternity agentJul 27, 2020
- CVE-2020-1559331Monitor
SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC.
HighCVSS 7.8No exploitEPSS 0%riverbed · steelcentral aternity agentJul 27, 2020
- CVE-2021-4285531Monitor
Local privilege escalation due to misconfigured write permission on .debug_command.config file
HighCVSS 7.8No exploitEPSS 0%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2017-769327Monitor
Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated
MediumCVSS 6.5No exploitEPSS 4%riverbed · opnet app response xpertAug 26, 2017
- CVE-2021-4327127Monitor
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when co
MediumCVSS 6.8No exploitEPSS 1%riverbed · appresponseJun 3, 2022
- CVE-2017-730727Monitor
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attac
MediumCVSS 6.8No exploitEPSS 0%riverbed · riosApr 4, 2017
- CVE-2017-730625Monitor
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to de
MediumCVSS 6.4No exploitEPSS 0%riverbed · riosApr 4, 2017
- CVE-2021-4285624Monitor
Reflected Cross-site Scripting at DsaDataTest
MediumCVSS 6.1No exploitEPSS 1%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2021-4285721Monitor
Directory Traversal Partial Write at AgentDaServlet
MediumCVSS 5.3No exploitEPSS 1%riverbed · steelcentral appinternals dynamic sampling agentMar 10, 2022
- CVE-2017-567018Monitor
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate
MediumCVSS 4.6No exploitEPSS 0%riverbed · riosApr 4, 2017
- CVE-2017-730518Monitor
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the s
MediumCVSS 4.6No exploitEPSS 0%riverbed · riosApr 4, 2017
- CVE-2014-534817Monitor
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6
MediumCVSS 4.3No exploitEPSS 1%riverbed · steelapp traffic managerAug 19, 2014