10

CVE-2020-24384

A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
A10networks ≫ Agalaxy Version >= 3.2.1 <= 3.2.4
A10networks ≫ Agalaxy Version >= 5.0.1 < 5.0.5
A10networks ≫ Agalaxy Version 3.0.1
A10networks ≫ Agalaxy Version 3.0.4 Update p3
A10networks ≫ Agalaxy Version 5.0.5 Update -
A10networks ≫ Advanced Core Operating System Version 3.2.2 Update -
A10networks ≫ Advanced Core Operating System Version 3.2.2 Update p8
A10networks ≫ Advanced Core Operating System Version 3.2.3 Update -
A10networks ≫ Advanced Core Operating System Version 3.2.3 Update p5
A10networks ≫ Advanced Core Operating System Version 3.2.4 Update -
A10networks ≫ Advanced Core Operating System Version 3.2.4 Update p5
A10networks ≫ Advanced Core Operating System Version 3.2.5 Update -
A10networks ≫ Advanced Core Operating System Version 3.2.5 Update p1
A10networks ≫ Advanced Core Operating System Version 4.0.0 Update -
A10networks ≫ Advanced Core Operating System Version 4.0.1 Update p3
A10networks ≫ Advanced Core Operating System Version 4.1.0 Update -
A10networks ≫ Advanced Core Operating System Version 4.1.0 Update p13
A10networks ≫ Advanced Core Operating System Version 4.1.1 Update -
A10networks ≫ Advanced Core Operating System Version 4.1.1 Update p13 Edition sp1
A10networks ≫ Advanced Core Operating System Version 4.1.2 Update -
A10networks ≫ Advanced Core Operating System Version 4.1.2 Update p5 Edition sp1
A10networks ≫ Advanced Core Operating System Version 4.1.4 Update -
A10networks ≫ Advanced Core Operating System Version 4.1.4 Update gr1-p4 Edition sp1
A10networks ≫ Advanced Core Operating System Version 4.1.100 Update -
A10networks ≫ Advanced Core Operating System Version 4.1.100 Update p7
A10networks ≫ Advanced Core Operating System Version 5.1.0 Update -
A10networks ≫ Advanced Core Operating System Version 5.1.0 Update p3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.53% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.a10networks.com/support/security_advisory/acos-agalaxy-gui-rce-vulnerability-cve-2020-24384
Patch
Vendor Advisory
Mitigation