Записи riverbed
17 опубликованных записей вендора riverbed.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-521 Weak Password Requirements2
- CWE-284 Improper Access Control1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-522 Insufficiently Protected Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-42786Эксплойта нет | Remote Code Execution at AgentControllerServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Критическая9,8 | — | 2,1 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2021-42853Эксплойта нет | Directory Traversal Delete/Read at AgentDiagnosticServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Критическая9,8 | — | 1,6 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2021-42854Эксплойта нет | Directory Traversal Read/Write/Delete at PluginServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Критическая9,8 | — | 1,6 % | 10 мар. 2022 г. |
39Наблюдать | CVE-2021-42787Эксплойта нет | Directory Traversal Write/Delete/Partial Read at AgentConfigurationServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Критическая9,8 | — | 1,3 % | 10 мар. 2022 г. |
32Наблюдать | CVE-2019-3800Эксплойта нет | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | Высокая7,8 | — | 2,1 % | 5 авг. 2019 г. |
31Наблюдать | CVE-2020-15592Эксплойта нет | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file.riverbed · steelcentral aternity agent · CWE-22 | Высокая7,5 | — | 1,9 % | 27 июл. 2020 г. |
31Наблюдать | CVE-2020-15593Эксплойта нет | SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC.riverbed · steelcentral aternity agent | Высокая7,8 | — | 0,4 % | 27 июл. 2020 г. |
31Наблюдать | CVE-2021-42855Эксплойта нет | Local privilege escalation due to misconfigured write permission on .debug_command.config fileriverbed · steelcentral appinternals dynamic sampling agent · CWE-284 | Высокая7,8 | — | 0,2 % | 10 мар. 2022 г. |
27Наблюдать | CVE-2017-7693Эксплойта нет | Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated riverbed · opnet app response xpert · CWE-22 | Средняя6,5 | — | 3,9 % | 26 авг. 2017 г. |
27Наблюдать | CVE-2021-43271Эксплойта нет | Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when coriverbed · appresponse · CWE-532 | Средняя6,8 | — | 0,8 % | 3 июн. 2022 г. |
27Наблюдать | CVE-2017-7307Эксплойта нет | Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attacriverbed · rios · CWE-732 | Средняя6,8 | — | 0,3 % | 4 апр. 2017 г. |
25Наблюдать | CVE-2017-7306Эксплойта нет | Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to deriverbed · rios · CWE-521 | Средняя6,4 | — | 0,4 % | 4 апр. 2017 г. |
24Наблюдать | CVE-2021-42856Эксплойта нет | Reflected Cross-site Scripting at DsaDataTestriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Средняя6,1 | — | 0,6 % | 10 мар. 2022 г. |
21Наблюдать | CVE-2021-42857Эксплойта нет | Directory Traversal Partial Write at AgentDaServletriverbed · steelcentral appinternals dynamic sampling agent · CWE-20 | Средняя5,3 | — | 1,2 % | 10 мар. 2022 г. |
18Наблюдать | CVE-2017-5670Эксплойта нет | Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate riverbed · rios · CWE-200 | Средняя4,6 | — | 0,4 % | 4 апр. 2017 г. |
18Наблюдать | CVE-2017-7305Эксплойта нет | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the sriverbed · rios · CWE-521 | Средняя4,6 | — | 0,3 % | 4 апр. 2017 г. |
17Наблюдать | CVE-2014-5348Эксплойта нет | Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6riverbed · steelapp traffic manager · CWE-79 | Средняя4,3 | — | 1,4 % | 19 авг. 2014 г. |
- CVE-2021-4278640В плане
Remote Code Execution at AgentControllerServlet
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2021-4285339Наблюдать
Directory Traversal Delete/Read at AgentDiagnosticServlet
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2021-4285439Наблюдать
Directory Traversal Read/Write/Delete at PluginServlet
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2021-4278739Наблюдать
Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2019-380032Наблюдать
CF CLI writes the client id and secret to config file
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %pivotal · cloud foundry command line interface5 авг. 2019 г.
- CVE-2020-1559231Наблюдать
SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %riverbed · steelcentral aternity agent27 июл. 2020 г.
- CVE-2020-1559331Наблюдать
SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %riverbed · steelcentral aternity agent27 июл. 2020 г.
- CVE-2021-4285531Наблюдать
Local privilege escalation due to misconfigured write permission on .debug_command.config file
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2017-769327Наблюдать
Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated
СредняяCVSS 6,5Эксплойта нетEPSS 4 %riverbed · opnet app response xpert26 авг. 2017 г.
- CVE-2021-4327127Наблюдать
Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when co
СредняяCVSS 6,8Эксплойта нетEPSS 1 %riverbed · appresponse3 июн. 2022 г.
- CVE-2017-730727Наблюдать
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attac
СредняяCVSS 6,8Эксплойта нетEPSS 0 %riverbed · rios4 апр. 2017 г.
- CVE-2017-730625Наблюдать
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to de
СредняяCVSS 6,4Эксплойта нетEPSS 0 %riverbed · rios4 апр. 2017 г.
- CVE-2021-4285624Наблюдать
Reflected Cross-site Scripting at DsaDataTest
СредняяCVSS 6,1Эксплойта нетEPSS 1 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2021-4285721Наблюдать
Directory Traversal Partial Write at AgentDaServlet
СредняяCVSS 5,3Эксплойта нетEPSS 1 %riverbed · steelcentral appinternals dynamic sampling agent10 мар. 2022 г.
- CVE-2017-567018Наблюдать
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate
СредняяCVSS 4,6Эксплойта нетEPSS 0 %riverbed · rios4 апр. 2017 г.
- CVE-2017-730518Наблюдать
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the s
СредняяCVSS 4,6Эксплойта нетEPSS 0 %riverbed · rios4 апр. 2017 г.
- CVE-2014-534817Наблюдать
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6
СредняяCVSS 4,3Эксплойта нетEPSS 1 %riverbed · steelapp traffic manager19 авг. 2014 г.