Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2020
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
CVSS Score
6.1
EPSS Score
0.005
Published
2020-04-15
RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
CVSS Score
4.8
EPSS Score
0.003
Published
2020-04-15
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
CVSS Score
7.9
EPSS Score
0.037
Published
2020-04-15
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
CVSS Score
6.0
EPSS Score
0.004
Published
2020-04-15
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.
CVSS Score
8.8
EPSS Score
0.006
Published
2020-04-15
NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.
CVSS Score
8.8
EPSS Score
0.003
Published
2020-04-15
NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.
CVSS Score
9.0
EPSS Score
0.001
Published
2020-04-15
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.
CVSS Score
7.7
EPSS Score
0.004
Published
2020-04-15
NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.
CVSS Score
4.2
EPSS Score
0.002
Published
2020-04-15
NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.
CVSS Score
4.2
EPSS Score
0.004
Published
2020-04-15


Contact Us

Shodan ® - All rights reserved