CVE-2020-5902 — F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
VulnWatch اطلاعات آسیبپذیری، امتیازها، نسخههای درگیر، راهکارها و دستورهای منتشرشده را از منابعی که در سامانه معرفی شدهاند گردآوری و برای دسترسی سادهتر نمایش میدهد. VulnWatch تولیدکننده یا مرجع اصلی این اطلاعات نیست.
ممکن است اطلاعات یک منبع ناقص، با تأخیر، تغییرکرده یا متناسب با محیط شما نباشد. VulnWatch صحت، کاملبودن، بهروز بودن یا نتیجه اجرای اطلاعات و دستورهای استخراجشده را تضمین نمیکند و مسئولیتی در قبال تصمیم، تغییر، اختلال یا خسارتی که صرفاً بر پایه این اطلاعات انجام شود نمیپذیرد.
پیش از نصب بهروزرسانی، اجرای دستور، تغییر تنظیمات یا هر اقدام عملیاتی، منبع اصلی را باز کنید، نسخه و محصول خود را تطبیق دهید، از اطلاعات مهم نسخه پشتیبان داشته باشید و تغییر را در محیط مناسب ارزیابی کنید.
آسیبپذیریها را بر اساس دستهبندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.
EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.
Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.
Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.