<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Unity (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/unity.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/unity-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Unity (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20035 – A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20035</guid>
    <pubDate>Wed, 06 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20035</strong></p>
  <p>A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device.  This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20034 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20034</guid>
    <pubDate>Wed, 06 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20034</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbit…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27478 – Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27478</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27478</strong></p>
  <p>Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21418 – Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21418</guid>
    <pubDate>Fri, 30 Jan 2026 09:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21418</strong></p>
  <p>Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20045 – A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20045</guid>
    <pubDate>Wed, 21 Jan 2026 17:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20045</strong></p>
  <p>A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlyin…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46423 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46423</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46423</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46422 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46422</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46422</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43942 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43942</guid>
    <pubDate>Thu, 30 Oct 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43942</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43941 – Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43941</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43941</strong></p>
  <p>Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability only affects systems without a valid license install.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43940 – Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43940</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43940</strong></p>
  <p>Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43939 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43939</guid>
    <pubDate>Thu, 30 Oct 2025 14:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43939</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59489 – Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows arg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59489</guid>
    <pubDate>Fri, 03 Oct 2025 14:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59489</strong></p>
  <p>Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that applic…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52800 – Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52800</guid>
    <pubDate>Thu, 14 Aug 2025 11:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52800</strong></p>
  <p>Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36607 – Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36607</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36607</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36606 – Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36606</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36606</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36604 – Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36604</guid>
    <pubDate>Mon, 04 Aug 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36604</strong></p>
  <p>Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52836 – Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Lt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52836</guid>
    <pubDate>Wed, 16 Jul 2025 12:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52836</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24386 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24386</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24386</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24385 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24385</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24385</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24381 – Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24381</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24381</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge se…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24380 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24380</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24380</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24379 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24379</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24379</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24378 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24378</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24378</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24377 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24377</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24377</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23383 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23383</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23383</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49601 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49601</guid>
    <pubDate>Fri, 28 Mar 2025 03:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49601</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24383 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24383</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24383</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24382 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24382</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24382</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-22398 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22398</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-22398</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critica…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49565 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49565</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49565</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49564 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49564</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49564</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49563 – Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49563</guid>
    <pubDate>Fri, 28 Mar 2025 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49563</strong></p>
  <p>Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31145 – Certain PCI devices in a system might be assigned Reserved Memory
Regions (speci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31145</guid>
    <pubDate>Wed, 25 Sep 2024 11:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31145</strong></p>
  <p>Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi.  These are typically used for platform tasks such as legacy USB emulation.  Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions n…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-4999 – A vulnerability in the web-based management interface of multiple Ligowave devic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4999</guid>
    <pubDate>Thu, 16 May 2024 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-4999</strong></p>
  <p>A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22228 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22228</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22228</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22227 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22227</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22227</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22225 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22225</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22225</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22224 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22224</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22224</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22223 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22223</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22223</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22222 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22222</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22222</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0170 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0170</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0170</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0168 – Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0168</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0168</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0167 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0167</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0167</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0166 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0166</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0166</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0165 – Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0165</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0165</strong></p>
  <p>Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-0164 – Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0164</guid>
    <pubDate>Mon, 12 Feb 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-0164</strong></p>
  <p>Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20272 – A vulnerability in the web-based management interface of Cisco Unity Connection ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20272</guid>
    <pubDate>Wed, 17 Jan 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20272</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of authentication in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43082 – Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43082</guid>
    <pubDate>Wed, 22 Nov 2023 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43082</strong></p>
  <p>Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-4804 – An unauthorized user could access debug features in Quantum HD Unity products th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4804</guid>
    <pubDate>Fri, 10 Nov 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-4804</strong></p>
  <p>An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37250 – Unity Parsec has a TOCTOU race condition that permits local attackers to escalat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37250</guid>
    <pubDate>Sun, 20 Aug 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37250</strong></p>
  <p>Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45788 – A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45788</guid>
    <pubDate>Mon, 30 Jan 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45788</strong></p>
  <p>A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37300 – A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37300</guid>
    <pubDate>Mon, 12 Sep 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37300</strong></p>
  <p>A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of E…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29084 – Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29084</guid>
    <pubDate>Thu, 02 Jun 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29084</strong></p>
  <p>Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by users.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22797 – A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22797</guid>
    <pubDate>Wed, 13 Apr 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22797</strong></p>
  <p>A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including for…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26361 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26361</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26361</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26360 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26360</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26360</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26359 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26359</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26359</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26358 – IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26358</guid>
    <pubDate>Tue, 05 Apr 2022 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26358</strong></p>
  <p>IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for p…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22792 – A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22792</guid>
    <pubDate>Thu, 02 Sep 2021 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22792</strong></p>
  <p>A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Mome…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22780 – Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22780</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22780</strong></p>
  <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause unauthorized access to a project file protected by a password when this file i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22779 – Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22779</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22779</strong></p>
  <p>Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*),…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22778 – Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22778</guid>
    <pubDate>Wed, 14 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22778</strong></p>
  <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause protected derived function blocks to be read or modified by unauthorized users…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1362 – A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1362</guid>
    <pubDate>Thu, 08 Apr 2021 04:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1362</strong></p>
  <p>A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM &amp; Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-29490 – Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29490</guid>
    <pubDate>Tue, 05 Jan 2021 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-29490</strong></p>
  <p>Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7560 – A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Contr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7560</guid>
    <pubDate>Fri, 11 Dec 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7560</strong></p>
  <p>A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-123</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7559 – A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7559</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7559</strong></p>
  <p>A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7538 – A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7538</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7538</strong></p>
  <p>A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28213 – A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28213</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28213</strong></p>
  <p>A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-28212 – A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28212</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-28212</strong></p>
  <p>A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28211 – A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28211</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28211</strong></p>
  <p>A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7498 – A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loade...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7498</guid>
    <pubDate>Tue, 16 Jun 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7498</strong></p>
  <p>A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized access to the file transfer service provided by the Modicon PLCs. This could result in various unintended results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7475 – A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7475</guid>
    <pubDate>Mon, 23 Mar 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7475</strong></p>
  <p>A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5319 – Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5319</guid>
    <pubDate>Thu, 06 Feb 2020 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5319</strong></p>
  <p>Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of Service (Storage Processor Panic) by sending an out of order SSH protocol sequence.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6855 – Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6855</guid>
    <pubDate>Mon, 06 Jan 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6855</strong></p>
  <p>Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9197 – The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9197</guid>
    <pubDate>Tue, 31 Dec 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9197</strong></p>
  <p>The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14960 – JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Edit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14960</guid>
    <pubDate>Tue, 01 Oct 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14960</strong></p>
  <p>JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3741 – Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3741</guid>
    <pubDate>Thu, 18 Jul 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3741</strong></p>
  <p>Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain a plain-text password storage vulnerability. A Unisphere user’s (including the admin privilege user) password is stored in a plain text in Unity Data Collection bundle (logs files for troubleshooting). A local authenticated attacker with access to the Data Collection bundle may use the exposed password to gain access with the pri…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15381 – A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15381</guid>
    <pubDate>Thu, 08 Nov 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15381</strong></p>
  <p>A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11064 – Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11064</guid>
    <pubDate>Fri, 05 Oct 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11064</strong></p>
  <p>Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability to alter multiple library files in service tools that might result in arbitrary code execution with elevated privileges. No user file systems are directly affected by th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1251 – Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1251</guid>
    <pubDate>Fri, 28 Sep 2018 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1251</strong></p>
  <p>Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from t…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-6779 – Multiple Cisco products are affected by a vulnerability in local file management...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-6779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-6779</guid>
    <pubDate>Thu, 07 Jun 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-6779</strong></p>
  <p>Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-6779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1239 – Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1239</guid>
    <pubDate>Tue, 08 May 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1239</strong></p>
  <p>Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system where Dell EMC Unity is installed.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1183 – In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1183</guid>
    <pubDate>Mon, 30 Apr 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1183</strong></p>
  <p>In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, Dell EMC VASA Provider Virtual Appliance versions prior to 8.4.0.512, Dell EMC SMIS versions prior to 8.4.0.6, Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4.0.347, Dell EMC VNX2 Operating Environment (OE) for File…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-12939 – A Remote Code Execution vulnerability was identified in all Windows versions of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12939</guid>
    <pubDate>Fri, 18 Aug 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-12939</strong></p>
  <p>A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8354 – An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8354</guid>
    <pubDate>Mon, 13 Feb 2017 21:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8354</strong></p>
  <p>An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instru…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0616 – The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0616</guid>
    <pubDate>Fri, 03 Apr 2015 18:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0616</strong></p>
  <p>The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) by improperly terminating SIP TCP connections, aka Bug ID CSCul69819.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0615 – The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0615</guid>
    <pubDate>Fri, 03 Apr 2015 18:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0615</strong></p>
  <p>The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID CSCul28089.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0614 – The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0614</guid>
    <pubDate>Fri, 03 Apr 2015 18:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0614</strong></p>
  <p>The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0613 – The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0613</guid>
    <pubDate>Fri, 03 Apr 2015 18:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0613</strong></p>
  <p>The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul20444.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-0612 – The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0612</guid>
    <pubDate>Fri, 03 Apr 2015 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-0612</strong></p>
  <p>The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU6, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (SIP outage) via a crafted UDP packet, aka Bug ID CSCuh25062.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-9200 – Stack-based buffer overflow in an unspecified DLL file in a DTM development kit ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9200</guid>
    <pubDate>Sun, 01 Feb 2015 15:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-9200</strong></p>
  <p>Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xan…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-3333 – The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3333</guid>
    <pubDate>Mon, 11 Aug 2014 20:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-3333</strong></p>
  <p>The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-5195 – Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5195</guid>
    <pubDate>Thu, 07 Aug 2014 11:13:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-5195</strong></p>
  <p>Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine that had text selected when locking or (2) resuming from a suspension.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0960 – Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0960</guid>
    <pubDate>Sat, 24 Nov 2012 20:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0960</strong></p>
  <p>Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-3060 – Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3060</guid>
    <pubDate>Sun, 16 Sep 2012 10:34:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-3060</strong></p>
  <p>Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0367 – Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0367</guid>
    <pubDate>Thu, 01 Mar 2012 01:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0367</strong></p>
  <p>Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-0366 – Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0366</guid>
    <pubDate>Thu, 01 Mar 2012 01:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-0366</strong></p>
  <p>Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-0931 – Schneider Electric Modicon Quantum PLC does not perform authentication between t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0931</guid>
    <pubDate>Sat, 28 Jan 2012 01:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-0931</strong></p>
  <p>Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-3330 – Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3330</guid>
    <pubDate>Fri, 04 Nov 2011 21:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-3330</strong></p>
  <p>Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4543 – Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4543</guid>
    <pubDate>Mon, 13 Oct 2008 20:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4543</strong></p>
  <p>Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to cause a denial of service (session exhaustion) via a large number of connections.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4543">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
