- EPSS 66.37%
- Veröffentlicht 16.04.2025 21:34:37
- Zuletzt bearbeitet 30.07.2025 19:24:19
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in S...
CVE-2021-1132
- EPSS 0.3%
- Veröffentlicht 18.11.2024 16:15:08
- Zuletzt bearbeitet 05.08.2025 13:21:24
A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management...
CVE-2022-20655
- EPSS 0.54%
- Veröffentlicht 15.11.2024 16:15:20
- Zuletzt bearbeitet 18.11.2024 17:11:56
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an a...
CVE-2024-20381
- EPSS 0.32%
- Veröffentlicht 11.09.2024 17:15:12
- Zuletzt bearbeitet 08.10.2024 21:43:28
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an...
CVE-2024-20326
- EPSS 0.43%
- Veröffentlicht 16.05.2024 14:15:08
- Zuletzt bearbeitet 25.07.2025 14:39:47
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerabilit...
CVE-2024-20389
- EPSS 0.14%
- Veröffentlicht 16.05.2024 14:15:08
- Zuletzt bearbeitet 30.07.2025 19:17:36
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerabilit...
CVE-2024-20366
- EPSS 0.15%
- Veröffentlicht 15.05.2024 18:15:09
- Zuletzt bearbeitet 25.03.2025 17:49:13
A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. Thi...
CVE-2024-20369
- EPSS 0.22%
- Veröffentlicht 15.05.2024 18:15:09
- Zuletzt bearbeitet 25.03.2025 17:44:05
A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input ...
CVE-2023-20040
- EPSS 1.41%
- Veröffentlicht 20.01.2023 07:15:15
- Zuletzt bearbeitet 21.11.2024 07:40:24
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability...
- EPSS 94.36%
- Veröffentlicht 10.12.2021 10:15:09
- Zuletzt bearbeitet 08.08.2025 18:52:00
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...