<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nexus Repository</title>
  <link>https://cvedaily.com/pages/tags/nexus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nexus.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nexus Repository</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:44 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-20171 – A vulnerability in the Border Gateway Protocol (BGP)&amp;nbsp;enforce-first-as featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20171</guid>
    <pubDate>Wed, 20 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20171</strong></p>
  <p>A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition.  This vulnerability is due to incorrect parsing of a transitive BGP attribute. An atta…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7308 – An authenticated user with upload permission to a hosted repository can store co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7308</guid>
    <pubDate>Mon, 11 May 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7308</strong></p>
  <p>An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the attacker to perform actions in the context of the victim's session.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3048 – An authenticated administrator who configures or tests LDAP connectivity in Sona...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3048</guid>
    <pubDate>Mon, 11 May 2026 18:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3048</strong></p>
  <p>An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43424 – In the Linux kernel, the following vulnerability has been resolved:

usb: gadget...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43424</guid>
    <pubDate>Fri, 08 May 2026 15:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43424</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_tcm: Fix NULL pointer dereferences in nexus handling  The `tpg->tpg_nexus` pointer in the USB Target driver is dynamically managed and tied to userspace configuration via ConfigFS. It can be NULL if the USB host sends requests before the nexus is fully established or immediately after it is dropped.  Currently, fu…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5189 – CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5189</guid>
    <pubDate>Wed, 15 Apr 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5189</strong></p>
  <p>CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3438 – A reflected cross-site scripting vulnerability exists in Sonatype Nexus Reposito...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3438</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3438</strong></p>
  <p>A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3199 – A vulnerability in the task management component of Sonatype Nexus Repository ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3199</guid>
    <pubDate>Wed, 08 Apr 2026 23:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3199</strong></p>
  <p>A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20174 – A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20174</guid>
    <pubDate>Wed, 01 Apr 2026 17:28:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20174</strong></p>
  <p>A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system.  This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a metadata update file and manually uploading it to an affected device. A successf…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20042 – A vulnerability in the configuration backup feature of Cisco Nexus Dashboard cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20042</guid>
    <pubDate>Wed, 01 Apr 2026 17:28:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20042</strong></p>
  <p>A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.  This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected devi…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20041 – A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20041</guid>
    <pubDate>Wed, 01 Apr 2026 17:28:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20041</strong></p>
  <p>A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20051 – A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20051</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20051</strong></p>
  <p>A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop.  This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by send…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20048 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20048</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20048</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper processing when parsing SNMP requests. An attacker could exploit this vulnerability by continuously sending SNMP q…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20033 – A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20033</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20033</strong></p>
  <p>A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to the&nbsp;management interfac…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0600 – Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0600</guid>
    <pubDate>Wed, 14 Jan 2026 23:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0600</strong></p>
  <p>Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A workaround configuration is available starting in version 3.88.0, but the product remai…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0601 – A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0601</guid>
    <pubDate>Wed, 14 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0601</strong></p>
  <p>A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-54154 – In the Linux kernel, the following vulnerability has been resolved:

scsi: targe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54154</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-54154</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: target: core: Fix target_cmd_counter leak  The target_cmd_counter struct allocated via target_alloc_cmd_counter() is never freed, resulting in leaks across various transport types, e.g.:   unreferenced object 0xffff88801f920120 (size 96):   comm "sh", pid 102, jiffies 4294892535 (age 713.412s)   hex dump (first 32 bytes):…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64142 – A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64142</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64142</strong></p>
  <p>A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64141 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64141</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64141</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9868 – Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9868</guid>
    <pubDate>Wed, 08 Oct 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9868</strong></p>
  <p>Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-39788 – In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39788</guid>
    <pubDate>Thu, 11 Sep 2025 17:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-39788</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE  On Google gs101, the number of UTP transfer request slots (nutrs) is 32, and in this case the driver ends up programming the UTRL_NEXUS_TYPE incorrectly as 0.  This is because the left hand side of the shift is 1, which is of type int, i.e. 31 bits wide. Shifting by more…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20348 – A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20348</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20348</strong></p>
  <p>A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device.  This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit th vulnerabili…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20347 – A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20347</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20347</strong></p>
  <p>A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device.  This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit th vulnerabili…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20344 – A vulnerability in the backup restore functionality of Cisco Nexus Dashboard cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20344</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20344</strong></p>
  <p>A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device.  This vulnerability is due to insufficient validation of the contents of a backup file. An attacker with valid Administrator credentials could exploit this vulnerability by restoring a crafted backup file to an affec…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20290 – A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20290</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20290</strong></p>
  <p>A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Series Switches in standalone NX-OS mode, Cisco UCS 6400 Fabric Interconnects, Cisco UCS 6500 Series Fabric Interconnects, and Cisco UCS 9108 100G Fabric Interconnects could allow an authenticated, local attacker access to sensitive information.  This vulnerability is due to imp…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20262 – A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20262</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20262</strong></p>
  <p>A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper processing of PIM6 ephemeral…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20241 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20241</guid>
    <pubDate>Wed, 27 Aug 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20241</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpectedly restart, which could cause an affected device to reload.  This vulnerability is due to insufficient…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-733</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38075 – In the Linux kernel, the following vulnerability has been resolved:

scsi: targe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38075</guid>
    <pubDate>Wed, 18 Jun 2025 10:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38075</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: target: iscsi: Fix timeout on deleted connection  NOPIN response timer may expire on a deleted connection and crash with such logs:  Did not receive response to NOPIN on CID: 0, failing connection for I_T Nexus (null),i,0x00023d000125,iqn.2017-01.com.iscsi.target,t,0x3d  BUG: Kernel NULL pointer dereference on read at 0x00…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20163 – A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20163</guid>
    <pubDate>Wed, 04 Jun 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20163</strong></p>
  <p>A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.  This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-322</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13945 – Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13945</guid>
    <pubDate>Fri, 23 May 2025 10:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13945</strong></p>
  <p>Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data  if administrator credentials become compromised.  This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51553 – Predictable filename vulnerabilities in ASPECT may expose sensitive information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51553</guid>
    <pubDate>Thu, 22 May 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51553</strong></p>
  <p>Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51552 – Weak password storage vulnerabilities exist in ASPECT if administrator credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51552</guid>
    <pubDate>Thu, 22 May 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51552</strong></p>
  <p>Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48848 – Large content vulnerabilities are present in ASPECT exposing a device to disk ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48848</guid>
    <pubDate>Thu, 22 May 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48848</strong></p>
  <p>Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-774</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13958 – Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13958</guid>
    <pubDate>Thu, 22 May 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13958</strong></p>
  <p>Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13957 – SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrato...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13957</guid>
    <pubDate>Thu, 22 May 2025 19:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13957</strong></p>
  <p>SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13956 – SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13956</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13956</strong></p>
  <p>SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13955 – 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13955</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13955</strong></p>
  <p>2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13954 – Serialized configuration information may be disclosed during device commissionin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13954</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13954</strong></p>
  <p>Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13953 – Sensitive device logger information in ASPECT may be exposed if administrator cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13953</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13953</strong></p>
  <p>Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13952 – Predictable filename vulnerabilities in ASPECT may expose sensitive information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13952</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13952</strong></p>
  <p>Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13951 – One way hash with predictable salt vulnerabilities in ASPECT may expose sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13951</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13951</strong></p>
  <p>One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13950 – Log injection vulnerabilities in ASPECT provide attacker access to inject malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13950</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13950</strong></p>
  <p>Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13949 – Large content vulnerabilities are present in ASPECT exposing a device to disk ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13949</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13949</strong></p>
  <p>Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13948 – Windows permissions for ASPECT configuration toolsets are not fully secured allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13948</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13948</strong></p>
  <p>Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13947 – Device commissioning parameters in ASPECT may be modified by an external source ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13947</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13947</strong></p>
  <p>Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13946 – DLL's are not digitally signed when loaded in ASPECT's configuration toolset exp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13946</guid>
    <pubDate>Thu, 22 May 2025 19:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13946</strong></p>
  <p>DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30173 – File upload vulnerabilities are present in ASPECT if session administrator crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30173</guid>
    <pubDate>Thu, 22 May 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30173</strong></p>
  <p>File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30172 – Remote Code Execution vulnerabilities are present in ASPECT if session administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30172</guid>
    <pubDate>Thu, 22 May 2025 18:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30172</strong></p>
  <p>Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30171 – System File Deletion vulnerabilities in ASPECT provide attackers access to delet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30171</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30171</strong></p>
  <p>System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30170 – Exposure of file path, file size or file existence vulnerabilities in ASPECT pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30170</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30170</strong></p>
  <p>Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30169 – File upload and execute vulnerabilities in ASPECT allow PHP script injection if ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30169</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30169</strong></p>
  <p>File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2410 – Port manipulation vulnerabilities in ASPECT provide attackers with the ability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2410</guid>
    <pubDate>Thu, 22 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2410</strong></p>
  <p>Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2409 – File corruption vulnerabilities in ASPECT provide attackers access to overwrite ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2409</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2409</strong></p>
  <p>File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-9639 – Remote Code Execution vulnerabilities are present in ASPECT if session administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9639</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-9639</strong></p>
  <p>Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13931 – Relative Path Traversal vulnerabilities in ASPECT allow access to file resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13931</guid>
    <pubDate>Thu, 22 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13931</strong></p>
  <p>Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-606</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13930 – An Unchecked Loop Condition in ASPECT provides an attacker the ability to malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13930</guid>
    <pubDate>Thu, 22 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13930</strong></p>
  <p>An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-606</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13929 – Servlet injection vulnerabilities in ASPECT allow remote code execution if sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13929</guid>
    <pubDate>Thu, 22 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13929</strong></p>
  <p>Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13928 – SQL injection vulnerabilities in ASPECT allow unintended access and manipulation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13928</guid>
    <pubDate>Thu, 22 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13928</strong></p>
  <p>SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48853 – An escalation of privilege vulnerability in ASPECT could provide an attacker roo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48853</guid>
    <pubDate>Thu, 22 May 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48853</strong></p>
  <p>An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48850 – Absolute File Traversal vulnerabilities in ASPECT allows access and modification...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48850</guid>
    <pubDate>Thu, 22 May 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48850</strong></p>
  <p>Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20150 – A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20150</guid>
    <pubDate>Wed, 16 Apr 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20150</strong></p>
  <p>A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts.  This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow an attacker to determine which usernames are valid LDA…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20161 – A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20161</guid>
    <pubDate>Wed, 26 Feb 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20161</strong></p>
  <p>A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of specific element…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20111 – A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20111</guid>
    <pubDate>Wed, 26 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20111</strong></p>
  <p>A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could ex…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51547 – Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51547</guid>
    <pubDate>Thu, 06 Feb 2025 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51547</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6784 – Server-Side Request Forgery vulnerabilities were found providing a potential for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6784</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6784</strong></p>
  <p>Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6516 – Cross Site Scripting vulnerabilities where found providing a potential for malic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6516</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6516</strong></p>
  <p>Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-6515 – Web browser interface may manipulate application username/password in clear text...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6515</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-6515</strong></p>
  <p>Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of  unintended credentails exposure.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51555 – Default Credentail vulnerabilities allows access to an Aspect device using publi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51555</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51555</strong></p>
  <p>Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1393</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51554 – Default Credentail vulnerabilities in ASPECT on Linux allows access to the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51554</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51554</strong></p>
  <p>Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51551 – Default Credentail vulnerabilities in ASPECT on Linux allows access to the produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51551</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51551</strong></p>
  <p>Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51550 – Data Validation / Data Sanitization  vulnerabilities in Linux allows unvalidated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51550</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51550</strong></p>
  <p>Data Validation / Data Sanitization  vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51549 – Absolute File Traversal  vulnerabilities allows access and modification of un-in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51549</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51549</strong></p>
  <p>Absolute File Traversal  vulnerabilities allows access and modification of un-intended resources.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51548 – Dangerous File Upload vulnerabilities allow upload of malicious scripts. 
Affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51548</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51548</strong></p>
  <p>Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51546 – Credentials Disclosure vulnerabilities allow access to on board project back-up ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51546</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51546</strong></p>
  <p>Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51545 – Username Enumeration vulnerabilities allow access to application level username ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51545</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51545</strong></p>
  <p>Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51544 – Service Control vulnerabilities allow access to service restart requests and vm ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51544</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51544</strong></p>
  <p>Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51543 – Information Disclosure vulnerabilities allow access to application configuration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51543</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51543</strong></p>
  <p>Information Disclosure vulnerabilities allow access to application configuration information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51542 – Configuration Download vulnerabilities allow access to dependency configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51542</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51542</strong></p>
  <p>Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51541 – Local File Inclusion vulnerabilities allow access to sensitive system informatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51541</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51541</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51541</strong></p>
  <p>Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51541">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48847 – MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48847</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48847</strong></p>
  <p>MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products:   ABB ASPECT - Enterprise v3.08.01;  NEXUS Series v3.08.01;  MATRIX Series v3.08.01</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48846 – Cross Site Request Forgery vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48846</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48846</strong></p>
  <p>Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48845 – Weak Password  Reset Rules vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48845</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48845</strong></p>
  <p>Weak Password  Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could  facilitate unauthorized admin/application access.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48844 – Denial of Service vulnerabilities where found providing a potiential for device ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48844</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48844</strong></p>
  <p>Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48843 – Denial of Service vulnerabilities where found providing a potiential for device ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48843</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48843</strong></p>
  <p>Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48840 – Unauthorized Access vulnerabilities allow Remote Code Execution. 
Affected produ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48840</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48840</strong></p>
  <p>Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48839 – Improper Input Validation vulnerability allows Remote Code Execution. 
Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48839</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48839</strong></p>
  <p>Improper Input Validation vulnerability allows Remote Code Execution.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-11317 – Session Fixation vulnerabilities allow an attacker to fix a users session identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11317</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-11317</strong></p>
  <p>Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11316 – Fileszie Check vulnerabilities allow a malicious user to bypass size limits or o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11316</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11316</strong></p>
  <p>Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products:   ABB ASPECT - Enterprise v3.08.02;  NEXUS Series v3.08.02;  MATRIX Series v3.08.02</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5082 – A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5082</guid>
    <pubDate>Thu, 14 Nov 2024 03:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5082</strong></p>
  <p>A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.   This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5083 – A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5083</guid>
    <pubDate>Thu, 14 Nov 2024 02:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5083</strong></p>
  <p>A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20536 – A vulnerability in a REST API endpoint and web-based management interface of Cis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20536</guid>
    <pubDate>Wed, 06 Nov 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20536</strong></p>
  <p>A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20371 – A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20371</guid>
    <pubDate>Wed, 06 Nov 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20371</strong></p>
  <p>A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should be blocked to the management interface of an affected device.&nbsp;  This vulnerability exists because ACL deny rules are not properly enforced at the time of device reboot. An attacker could exploit this vulnerability by attempt…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5764 – Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has bee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5764</guid>
    <pubDate>Wed, 23 Oct 2024 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5764</strong></p>
  <p>Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded encryption passphrase. While it was possible for an administrator to define an a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20491 – A vulnerability in a logging function of Cisco Nexus Dashboard Insights could al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20491</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20491</strong></p>
  <p>A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information.  This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnerability by accessing a tech support file that is generated f…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20490 – A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20490</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20490</strong></p>
  <p>A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information.  This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech support file. An attacker could exploit this vulnera…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20449 – A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20449</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20449</strong></p>
  <p>A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device.  This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol (SCP) to upload malicious code to an affected device using path traversal techniq…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20448 – A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20448</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20448</strong></p>
  <p>A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information.  This vulnerability is due to the improper storage of sensitive information within config only and full backup files. An attacker could exploit this vulnerability by parsing the cont…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-313</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20444 – A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20444</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20444</strong></p>
  <p>A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to insufficient validation of command arguments. An attacker could exploit this vulnerability by submitt…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20442 – A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20442</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20442</strong></p>
  <p>A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device.  This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending crafted API requests to an affected endpoint. A succes…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-20432 – A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Contr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20432</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-20432</strong></p>
  <p>A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting cra…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20385 – A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20385</guid>
    <pubDate>Wed, 02 Oct 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20385</strong></p>
  <p>A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected device.&nbsp;  This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisc…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20385">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
