<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nexus Repository (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/nexus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nexus-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nexus Repository (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-5189 – CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5189</guid>
    <pubDate>Wed, 15 Apr 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5189</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3199 – A vulnerability in the task management component of Sonatype Nexus Repository ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3199</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3199</strong></p>
  <p>A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20051 – A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20051</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20051</strong></p>
  <p>A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop.  This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by send…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20048 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20048</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20048</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper processing when parsing SNMP requests. An attacker could exploit this vulnerability by continuously sending SNMP q…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20033 – A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20033</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20033</strong></p>
  <p>A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to the&nbsp;management interfac…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9868 – Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9868</guid>
    <pubDate>Wed, 08 Oct 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9868</strong></p>
  <p>Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-39788 – In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39788</guid>
    <pubDate>Thu, 11 Sep 2025 17:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-39788</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE  On Google gs101, the number of UTP transfer request slots (nutrs) is 32, and in this case the driver ends up programming the UTRL_NEXUS_TYPE incorrectly as 0.  This is because the left hand side of the shift is 1, which is of type int, i.e. 31 bits wide. Shifting by more…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20241 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20241</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20241</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload.  This vulnerability is due to insufficient…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-733</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20163 – A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20163</guid>
    <pubDate>Wed, 04 Jun 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20163</strong></p>
  <p>A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.  This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-322</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13957 – SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrato...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13957</guid>
    <pubDate>Thu, 22 May 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13957</strong></p>
  <p>SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13955 – 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13955</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13955</strong></p>
  <p>2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13952 – Predictable filename vulnerabilities in ASPECT may expose sensitive information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13952</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13952</strong></p>
  <p>Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13951 – One way hash with predictable salt vulnerabilities in ASPECT may expose sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13951</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13951</strong></p>
  <p>One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13948 – Windows permissions for ASPECT configuration toolsets are not fully secured allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13948</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13948</strong></p>
  <p>Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30172 – Remote Code Execution vulnerabilities are present in ASPECT if session administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30172</guid>
    <pubDate>Thu, 22 May 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30172</strong></p>
  <p>Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30171 – System File Deletion vulnerabilities in ASPECT provide attackers access to delet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30171</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30171</strong></p>
  <p>System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2410 – Port manipulation vulnerabilities in ASPECT provide attackers with the ability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2410</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2410</strong></p>
  <p>Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2409 – File corruption vulnerabilities in ASPECT provide attackers access to overwrite ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2409</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2409</strong></p>
  <p>File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9639 – Remote Code Execution vulnerabilities are present in ASPECT if session administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9639</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9639</strong></p>
  <p>Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13931 – Relative Path Traversal vulnerabilities in ASPECT allow access to file resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13931</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13931</strong></p>
  <p>Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-606</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13929 – Servlet injection vulnerabilities in ASPECT allow remote code execution if sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13929</guid>
    <pubDate>Thu, 22 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13929</strong></p>
  <p>Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13928 – SQL injection vulnerabilities in ASPECT allow unintended access and manipulation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13928</guid>
    <pubDate>Thu, 22 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13928</strong></p>
  <p>SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48853 – An escalation of privilege vulnerability in ASPECT could provide an attacker roo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48853</guid>
    <pubDate>Thu, 22 May 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48853</strong></p>
  <p>An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48850 – Absolute File Traversal vulnerabilities in ASPECT allows access and modification...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48850</guid>
    <pubDate>Thu, 22 May 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48850</strong></p>
  <p>Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20111 – A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20111</guid>
    <pubDate>Wed, 26 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20111</strong></p>
  <p>A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could ex…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51547 – Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51547</guid>
    <pubDate>Thu, 06 Feb 2025 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51547</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6784 – Server-Side Request Forgery vulnerabilities were found providing a potential for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6784</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6784</strong></p>
  <p>Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6516 – Cross Site Scripting vulnerabilities where found providing a potential for malic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6516</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6516</strong></p>
  <p>Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6515 – Web browser interface may manipulate application username/password in clear text...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6515</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6515</strong></p>
  <p>Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of  unintended credentails exposure.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51555 – Default Credentail vulnerabilities allows access to an Aspect device using publi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51555</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51555</strong></p>
  <p>Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51554 – Default Credentail vulnerabilities in ASPECT on Linux allows access to the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51554</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51554</strong></p>
  <p>Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51551 – Default Credentail vulnerabilities in ASPECT on Linux allows access to the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51551</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51551</strong></p>
  <p>Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51550 – Data Validation / Data Sanitization  vulnerabilities in Linux allows unvalidated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51550</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51550</strong></p>
  <p>Data Validation / Data Sanitization  vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51549 – Absolute File Traversal  vulnerabilities allows access and modification of un-in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51549</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51549</strong></p>
  <p>Absolute File Traversal  vulnerabilities allows access and modification of un-intended resources.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51548 – Dangerous File Upload vulnerabilities allow upload of malicious scripts. 
Affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51548</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51548</strong></p>
  <p>Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51546 – Credentials Disclosure vulnerabilities allow access to on board project back-up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51546</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51546</strong></p>
  <p>Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51545 – Username Enumeration vulnerabilities allow access to application level username ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51545</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51545</strong></p>
  <p>Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51544 – Service Control vulnerabilities allow access to service restart requests and vm ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51544</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51544</strong></p>
  <p>Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51543 – Information Disclosure vulnerabilities allow access to application configuration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51543</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51543</strong></p>
  <p>Information Disclosure vulnerabilities allow access to application configuration information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51542 – Configuration Download vulnerabilities allow access to dependency configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51542</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51542</strong></p>
  <p>Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51541 – Local File Inclusion vulnerabilities allow access to sensitive system informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51541</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51541</strong></p>
  <p>Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48847 – MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48847</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48847</strong></p>
  <p>MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products:   ABB ASPECT - Enterprise v3.08.01;  NEXUS Series v3.08.01;  MATRIX Series v3.08.01</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48846 – Cross Site Request Forgery vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48846</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48846</strong></p>
  <p>Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48845 – Weak Password  Reset Rules vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48845</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48845</strong></p>
  <p>Weak Password  Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could  facilitate unauthorized admin/application access.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48844 – Denial of Service vulnerabilities where found providing a potiential for device ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48844</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48844</strong></p>
  <p>Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48843 – Denial of Service vulnerabilities where found providing a potiential for device ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48843</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48843</strong></p>
  <p>Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48840 – Unauthorized Access vulnerabilities allow Remote Code Execution. 
Affected produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48840</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48840</strong></p>
  <p>Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48839 – Improper Input Validation vulnerability allows Remote Code Execution. 
Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48839</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48839</strong></p>
  <p>Improper Input Validation vulnerability allows Remote Code Execution.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-11317 – Session Fixation vulnerabilities allow an attacker to fix a users session identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11317</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-11317</strong></p>
  <p>Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11316 – Fileszie Check vulnerabilities allow a malicious user to bypass size limits or o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11316</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11316</strong></p>
  <p>Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5082 – A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5082</guid>
    <pubDate>Thu, 14 Nov 2024 03:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5082</strong></p>
  <p>A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.   This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20536 – A vulnerability in a REST API endpoint and web-based management interface of Cis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20536</guid>
    <pubDate>Wed, 06 Nov 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20536</strong></p>
  <p>A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20449 – A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20449</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20449</strong></p>
  <p>A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device.  This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol (SCP) to upload malicious code to an affected device using path traversal techniq…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-20432 – A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Contr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20432</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-20432</strong></p>
  <p>A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting cra…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6298 – Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6298</guid>
    <pubDate>Fri, 05 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6298</strong></p>
  <p>Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series   v3.08.01  ; MATRIX Series    v3.08.01 allows Attacker to execute arbitrary code remotely</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6209 – Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6209</guid>
    <pubDate>Fri, 05 Jul 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6209</strong></p>
  <p>Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series   v3.08.01  ; MATRIX Series    v3.08.01 allows Attacker to access files unauthorized</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4007 – Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4007</guid>
    <pubDate>Mon, 01 Jul 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4007</strong></p>
  <p>Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-30163 – Invision Community before 4.7.16 allow SQL injection via the applications/nexus/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30163</guid>
    <pubDate>Fri, 07 Jun 2024 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-30163</strong></p>
  <p>Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4956 – Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4956</guid>
    <pubDate>Thu, 16 May 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4956</strong></p>
  <p>Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20348 – A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20348</guid>
    <pubDate>Wed, 03 Apr 2024 17:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20348</strong></p>
  <p>A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files.  This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through direct web requests to the provisioning server. A successful exploit could all…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-27</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20281 – A vulnerability in the web-based management interface of Cisco Nexus Dashboard a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20281</guid>
    <pubDate>Wed, 03 Apr 2024 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20281</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.  This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit thi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50768 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50768</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50768</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50766 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50766</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50766</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20169 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protoc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20169</guid>
    <pubDate>Wed, 23 Aug 2023 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20169</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload.  This vulnerability is due to insuffi…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-788</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20185 – A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20185</guid>
    <pubDate>Wed, 12 Jul 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20185</strong></p>
  <p>A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.  This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-pat…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0636 – Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0636</guid>
    <pubDate>Mon, 05 Jun 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0636</strong></p>
  <p>Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG1…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0635 – Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on AS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0635</guid>
    <pubDate>Mon, 05 Jun 2023 04:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0635</strong></p>
  <p>Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20014 – A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20014</guid>
    <pubDate>Wed, 01 Mar 2023 08:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20014</strong></p>
  <p>A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.  This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of DNS requests to an affected device. A successful exploit could allow the attac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20089 – A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20089</guid>
    <pubDate>Thu, 23 Feb 2023 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20089</strong></p>
  <p>A vulnerability in the Link Layer Discovery Protocol (LLDP) feature for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to cause a memory leak, which could result in an unexpected reload of the device. This vulnerability is due to incorrect error checking when parsing ingress LLDP packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36030 – Project-nexus is a general-purpose blog website framework. Affected versions are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36030</guid>
    <pubDate>Sat, 20 Aug 2022 00:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36030</strong></p>
  <p>Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-20861 – Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20861</guid>
    <pubDate>Thu, 21 Jul 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-20861</strong></p>
  <p>Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20860 – A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20860</guid>
    <pubDate>Thu, 21 Jul 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20860</strong></p>
  <p>A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is establishing a connection to Cisco Application Policy Infrastructure Controller (APIC), Cis…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-20858 – Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20858</guid>
    <pubDate>Thu, 21 Jul 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-20858</strong></p>
  <p>Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-20857 – Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20857</guid>
    <pubDate>Thu, 21 Jul 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-20857</strong></p>
  <p>Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20623 – A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20623</guid>
    <pubDate>Wed, 23 Feb 2022 18:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20623</strong></p>
  <p>A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is due to a logic error in the BFD rate limiter functionality. An attacker could exploit this vulnerability by sending a cra…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40143 – Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40143</guid>
    <pubDate>Tue, 07 Sep 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40143</strong></p>
  <p>Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1586 – A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1586</guid>
    <pubDate>Wed, 25 Aug 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1586</strong></p>
  <p>A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resulting in a denial of service (DoS) condition. This vulnerability exists because TCP traffic sent to a specific port on an affected device is not pro…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1523 – A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1523</guid>
    <pubDate>Wed, 25 Aug 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1523</strong></p>
  <p>A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control plane traffic to the device being dropped. This could result in one or more leaf switches being removed from the fabric. This vulnerability is due to mishandling o…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37167 – An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37167</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37167</strong></p>
  <p>An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. A user logged in using the default credentials can gain root access to the device, which provides permissions for all of the functionality of the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37166 – A buffer overflow issue leading to denial of service was discovered in HMI3 Cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37166</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37166</strong></p>
  <p>A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37164 – A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37164</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37164</strong></p>
  <p>A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37163 – An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37163</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37163</strong></p>
  <p>An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37162 – A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37162</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37162</strong></p>
  <p>A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. If an attacker sends a malformed UDP message, a buffer underflow occurs, leading to an out-of-bounds copy and possible remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37161 – A buffer overflow issue was discovered in the HMI3 Control Panel contained withi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37161</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37161</strong></p>
  <p>A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37160 – A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Hea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37160</guid>
    <pubDate>Mon, 02 Aug 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37160</strong></p>
  <p>A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-37165 – A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37165</guid>
    <pubDate>Mon, 02 Aug 2021 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-37165</strong></p>
  <p>A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-1361 – A vulnerability in the implementation of an internal file management service for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1361</guid>
    <pubDate>Wed, 24 Feb 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-1361</strong></p>
  <p>A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode that are running Cisco NX-OS Software could allow an unauthenticated, remote attacker to create, delete, or overwrite arbitrary files with root privileges on the device. This vulnerability exists because TCP port 9075 is in…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1230 – A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Seri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1230</guid>
    <pubDate>Wed, 24 Feb 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1230</strong></p>
  <p>A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denial of service (DoS) condition. This vulnerability is due to an issue with the installation of routes upon receipt of a BGP update. An attack…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-233</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1228 – A vulnerability in the fabric infrastructure VLAN connection establishment of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1228</guid>
    <pubDate>Wed, 24 Feb 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1228</strong></p>
  <p>A vulnerability in the fabric infrastructure VLAN connection establishment of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. This vulnerability is due to insufficient security requirements during the Link Layer Di…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-0016 – In the Broadcom Nexus firmware, there is an insecure default password. This coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-0016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-0016</guid>
    <pubDate>Mon, 14 Dec 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-0016</strong></p>
  <p>In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413483</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-0016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15012 – A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15012</guid>
    <pubDate>Mon, 12 Oct 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15012</strong></p>
  <p>A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3394 – A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3394</guid>
    <pubDate>Thu, 27 Aug 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3394</strong></p>
  <p>A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to issue the enable command and get full administrative privileges. To exploit this vulnerability, the attacker would need to have valid credentials for the affected device. The vulnerability is due to a logic e…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15868 – Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15868</guid>
    <pubDate>Wed, 12 Aug 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15868</strong></p>
  <p>Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15871 – Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15871</guid>
    <pubDate>Fri, 31 Jul 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15871</strong></p>
  <p>Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11753 – An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11753</guid>
    <pubDate>Mon, 20 Apr 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11753</strong></p>
  <p>An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11444 – Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11444</guid>
    <pubDate>Thu, 02 Apr 2020 18:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11444</strong></p>
  <p>Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10204 – Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10204</guid>
    <pubDate>Wed, 01 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10204</strong></p>
  <p>Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10199 – Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10199</guid>
    <pubDate>Wed, 01 Apr 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10199</strong></p>
  <p>Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3168 – A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3168</guid>
    <pubDate>Wed, 26 Feb 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3168</strong></p>
  <p>A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The vulnerability is due to improper resource allocation during failed CLI login attempts when login parameters that are part of t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3314 – The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresse...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3314</guid>
    <pubDate>Thu, 21 Nov 2019 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3314</strong></p>
  <p>The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3314">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
