Записи Airspan
21 опубликованных записей вендора airspan.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-255 Credentials Management Errors2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2022-36267Proof of concept | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.airspan · airspot 5410 firmware | Критическая9,8 | — | 54,5 % | 8 авг. 2022 г. |
43В плане | CVE-2008-1262Proof of concept | The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allairspan · wimax prost · CWE-287 | Критическая10,0 | — | 8,5 % | 10 мар. 2008 г. |
42В плане | CVE-2022-36309Эксплойта нет | Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter ofairspan · airvelocity 1500 firmware · CWE-78 | Высокая8,8 | — | 24,6 % | 15 авг. 2022 г. |
40В плане | CVE-2022-21196Эксплойта нет | Airspan Networks Mimosa Improper Authorizationairspan · mimosa management platform · CWE-285 | Критическая9,8 | — | 3,7 % | 18 февр. 2022 г. |
40В плане | CVE-2022-21141Эксплойта нет | Airspan Networks Mimosa Incorrect Authorizationairspan · mimosa management platform · CWE-863 | Критическая9,8 | — | 3,2 % | 18 февр. 2022 г. |
39Наблюдать | CVE-2022-21215Эксплойта нет | Airspan Networks Mimosa Server-Side Request Forgery (SSRF)airspan · mimosa management platform · CWE-918 | Критическая9,8 | — | 1,4 % | 18 февр. 2022 г. |
39Наблюдать | CVE-2022-21143Эксплойта нет | Airspan Networks Mimosa OS Command Injectionairspan · mimosa management platform · CWE-78 | Критическая9,8 | — | 1,2 % | 18 февр. 2022 г. |
36Наблюдать | CVE-2022-36264Эксплойта нет | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows airspan · airspot 5410 firmware · CWE-434 | Критическая9,1 | — | 1,6 % | 8 авг. 2022 г. |
36Наблюдать | CVE-2022-36308Эксплойта нет | Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores airspan · airvelocity 1500 firmware · CWE-256 | Критическая9,1 | — | 0,7 % | 15 авг. 2022 г. |
35Наблюдать | CVE-2022-36310Эксплойта нет | Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker airspan · airvelocity 1500 firmware · CWE-242 | Высокая8,8 | — | 1,5 % | 15 авг. 2022 г. |
35Наблюдать | CVE-2022-36312Эксплойта нет | Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI.airspan · airvelocity 1500 firmware · CWE-352 | Высокая8,8 | — | 0,3 % | 15 авг. 2022 г. |
31Наблюдать | CVE-2008-1542Эксплойта нет | Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain airspan · base station distribution unit · CWE-255 | Высокая7,5 | — | 1,8 % | 28 мар. 2008 г. |
30Наблюдать | CVE-2008-1543Эксплойта нет | The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and passwoairspan · easy st · CWE-255 | Высокая7,5 | — | 1,2 % | 28 мар. 2008 г. |
30Наблюдать | CVE-2022-21176Эксплойта нет | Airspan Networks Mimosa SQL Injectionairspan · mimosa management platform · CWE-89 | Высокая7,5 | — | 1,1 % | 18 февр. 2022 г. |
30Наблюдать | CVE-2022-0138Эксплойта нет | Airspan Networks Mimosa Deserialization of Untrusted Dataairspan · mimosa management platform · CWE-502 | Высокая7,5 | — | 1,0 % | 18 февр. 2022 г. |
28Наблюдать | CVE-2022-36265Эксплойта нет | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page.airspan · airspot 5410 firmware | Высокая7,2 | — | 1,4 % | 8 авг. 2022 г. |
27Наблюдать | CVE-2022-36307Эксплойта нет | The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.airspan · airvelocity 1500 firmware · CWE-522 | Средняя6,8 | — | 0,3 % | 15 авг. 2022 г. |
26Наблюдать | CVE-2022-36306Эксплойта нет | An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web seairspan · airvelocity 1500 firmware · CWE-219 | Средняя6,5 | — | 1,0 % | 15 авг. 2022 г. |
26Наблюдать | CVE-2022-21800Эксплойта нет | Airspan Networks Mimosa Use of a Broken or Risky Cryptographic Algorithmairspan · mimosa management platform · CWE-327 | Средняя6,5 | — | 0,5 % | 18 февр. 2022 г. |
24Наблюдать | CVE-2022-36266Эксплойта нет | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability.airspan · airspot 5410 firmware · CWE-79 | Средняя6,1 | — | 1,0 % | 8 авг. 2022 г. |
24Наблюдать | CVE-2022-36311Эксплойта нет | Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in thairspan · airvelocity 1500 firmware · CWE-79 | Средняя6,1 | — | 0,4 % | 15 авг. 2022 г. |
- CVE-2022-3626755В плане
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 55 %airspan · airspot 5410 firmware8 авг. 2022 г.
- CVE-2008-126243В плане
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which all
КритическаяCVSS 10,0Proof of conceptEPSS 9 %airspan · wimax prost10 мар. 2008 г.
- CVE-2022-3630942В плане
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of
ВысокаяCVSS 8,8Эксплойта нетEPSS 25 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2022-2119640В плане
Airspan Networks Mimosa Improper Authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-2114140В плане
Airspan Networks Mimosa Incorrect Authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-2121539Наблюдать
Airspan Networks Mimosa Server-Side Request Forgery (SSRF)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-2114339Наблюдать
Airspan Networks Mimosa OS Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-3626436Наблюдать
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %airspan · airspot 5410 firmware8 авг. 2022 г.
- CVE-2022-3630836Наблюдать
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2022-3631035Наблюдать
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2022-3631235Наблюдать
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2008-154231Наблюдать
Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %airspan · base station distribution unit28 мар. 2008 г.
- CVE-2008-154330Наблюдать
The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and passwo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %airspan · easy st28 мар. 2008 г.
- CVE-2022-2117630Наблюдать
Airspan Networks Mimosa SQL Injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-013830Наблюдать
Airspan Networks Mimosa Deserialization of Untrusted Data
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-3626528Наблюдать
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %airspan · airspot 5410 firmware8 авг. 2022 г.
- CVE-2022-3630727Наблюдать
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2022-3630626Наблюдать
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web se
СредняяCVSS 6,5Эксплойта нетEPSS 1 %airspan · airvelocity 1500 firmware15 авг. 2022 г.
- CVE-2022-2180026Наблюдать
Airspan Networks Mimosa Use of a Broken or Risky Cryptographic Algorithm
СредняяCVSS 6,5Эксплойта нетEPSS 1 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2022-3626624Наблюдать
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %airspan · airspot 5410 firmware8 авг. 2022 г.
- CVE-2022-3631124Наблюдать
Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in th
СредняяCVSS 6,1Эксплойта нетEPSS 0 %airspan · airvelocity 1500 firmware15 авг. 2022 г.