Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging knowledge of the credentials, aka Bug ID CSCuw21825.
Monthly Archives: September 2015
CVE-2015-6297
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
CVE-2015-6456
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
CVE-2015-6459
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
CVE-2015-6460
Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.47 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.
CVE-2015-6932
VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Bugtraq: APPLE-SA-2015-09-16-4 OS X Server 5.0.3
APPLE-SA-2015-09-16-4 OS X Server 5.0.3
Bugtraq: Apple Safari FTP PASV manipulation vulnerability (CVE-2015-5912)
Apple Safari FTP PASV manipulation vulnerability (CVE-2015-5912)
Bugtraq: KL-001-2015-005 : VBox Satellite Express Arbitrary Write Privilege Escalation
KL-001-2015-005 : VBox Satellite Express Arbitrary Write Privilege Escalation
Bugtraq: [security bulletin] HPSBST03418 rev.1 – HP P6000 Command View Software, Remote Disclosure of Information
[security bulletin] HPSBST03418 rev.1 – HP P6000 Command View Software, Remote Disclosure of Information