untangle kayıtları
untangle üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-326 Inadequate Encryption Strength1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
29İzleyin | CVE-2019-18647İstismar yok | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.untangle · ng firewall · CWE-77 | Yüksek7,2 | — | %1,9 | 14 Kas 2019 |
28İzleyin | CVE-2019-18646İstismar yok | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lountangle · ng firewall · CWE-89 | Yüksek7,2 | — | %0,9 | 14 Kas 2019 |
21İzleyin | CVE-2020-17494İstismar yok | Untangle Firewall NG before 16.0 uses MD5 for passwords.untangle · untangle firewall ng · CWE-326 | Orta5,3 | — | %0,8 | 12 Kas 2020 |
19İzleyin | CVE-2019-18648İstismar yok | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input funtangle · ng firewall · CWE-79 | Orta4,8 | — | %0,5 | 14 Kas 2019 |
19İzleyin | CVE-2019-18649İstismar yok | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.untangle · ng firewall · CWE-79 | Orta4,8 | — | %0,5 | 14 Kas 2019 |
- CVE-2019-1864729İzleyin
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
YüksekCVSS 7,2İstismar yokEPSS %2untangle · ng firewall14 Kas 2019
- CVE-2019-1864628İzleyin
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lo
YüksekCVSS 7,2İstismar yokEPSS %1untangle · ng firewall14 Kas 2019
- CVE-2020-1749421İzleyin
Untangle Firewall NG before 16.0 uses MD5 for passwords.
OrtaCVSS 5,3İstismar yokEPSS %1untangle · untangle firewall ng12 Kas 2020
- CVE-2019-1864819İzleyin
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input f
OrtaCVSS 4,8İstismar yokEPSS %1untangle · ng firewall14 Kas 2019
- CVE-2019-1864919İzleyin
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
OrtaCVSS 4,8İstismar yokEPSS %1untangle · ng firewall14 Kas 2019