Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2019
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
CVSS Score
8.8
EPSS Score
0.001
Published
2019-08-27
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
CVSS Score
4.3
EPSS Score
0.003
Published
2019-08-27
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
CVSS Score
8.8
EPSS Score
0.001
Published
2019-08-27
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-27
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-27
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-08-27
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-08-27
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in acknowledge.c.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-08-27
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-08-27
In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-08-27


Contact Us

Shodan ® - All rights reserved