|
246781
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios_xe ios
|
A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the internal VTP database on…
|
CWE-20
Improper Input Validation
|
CVE-2018-0197
|
2024-11-21 12:37 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246782
|
5.9 |
MEDIUM
Network
|
cisco
|
ios ios_xe
|
A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Inte…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2018-0131
|
2024-11-21 12:37 |
2018-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246783
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-0042
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246784
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to in…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0041
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246785
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized ac…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0040
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246786
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorize…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0039
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246787
|
9.8 |
CRITICAL
Network
|
juniper
|
contrail_service_orchestration
|
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthori…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-0038
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246788
|
5.9 |
MEDIUM
Network
|
juniper
|
junos
|
Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When RPD is unavailable, routing updates cannot be processed which can lead to an ext…
|
CWE-20
Improper Input Validation
|
CVE-2018-0027
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246789
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. By continuously sending crafted BGP NOTI…
|
CWE-20
Improper Input Validation
|
CVE-2018-0037
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246790
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
QFX5200 and QFX10002 devices that have been shipped with Junos OS 15.1X53-D21, 15.1X53-D30, 15.1X53-D31, 15.1X53-D32, 15.1X53-D33 and 15.1X53-D60 or have been upgraded to these releases using the .bi…
|
NVD-CWE-noinfo
|
CVE-2018-0035
|
2024-11-21 12:37 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|