Записи untangle
5 опубликованных записей вендора untangle.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-326 Inadequate Encryption Strength1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
29Наблюдать | CVE-2019-18647Эксплойта нет | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.untangle · ng firewall · CWE-77 | Высокая7,2 | — | 1,9 % | 14 нояб. 2019 г. |
28Наблюдать | CVE-2019-18646Эксплойта нет | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lountangle · ng firewall · CWE-89 | Высокая7,2 | — | 0,9 % | 14 нояб. 2019 г. |
21Наблюдать | CVE-2020-17494Эксплойта нет | Untangle Firewall NG before 16.0 uses MD5 for passwords.untangle · untangle firewall ng · CWE-326 | Средняя5,3 | — | 0,8 % | 12 нояб. 2020 г. |
19Наблюдать | CVE-2019-18648Эксплойта нет | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input funtangle · ng firewall · CWE-79 | Средняя4,8 | — | 0,5 % | 14 нояб. 2019 г. |
19Наблюдать | CVE-2019-18649Эксплойта нет | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.untangle · ng firewall · CWE-79 | Средняя4,8 | — | 0,5 % | 14 нояб. 2019 г. |
- CVE-2019-1864729Наблюдать
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %untangle · ng firewall14 нояб. 2019 г.
- CVE-2019-1864628Наблюдать
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lo
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %untangle · ng firewall14 нояб. 2019 г.
- CVE-2020-1749421Наблюдать
Untangle Firewall NG before 16.0 uses MD5 for passwords.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %untangle · untangle firewall ng12 нояб. 2020 г.
- CVE-2019-1864819Наблюдать
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input f
СредняяCVSS 4,8Эксплойта нетEPSS 1 %untangle · ng firewall14 нояб. 2019 г.
- CVE-2019-1864919Наблюдать
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %untangle · ng firewall14 нояб. 2019 г.