| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39100 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39099 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39098 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39097 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39096 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39095 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39094 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39093 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39092 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39091 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-39090 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. | ||
| CVE-2022-25912 | Hig | 0.46 | 8.1 | 0.03 | Dec 6, 2022 | The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS… | ||
| CVE-2022-24439 | Hig | 0.46 | 8.1 | 0.05 | Dec 6, 2022 | All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes… | ||
| CVE-2022-4173 | Hig | 0.48 | 7.3 | 0.01 | Dec 6, 2022 | A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10. | ||
| CVE-2022-45283 | Hig | 0.51 | 7.8 | 0.00 | Dec 6, 2022 | GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c. | ||
| CVE-2022-44009 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information. | ||
| CVE-2022-38336 | Hig | 0.53 | 8.1 | 0.01 | Dec 6, 2022 | An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication. | ||
| CVE-2021-39434 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220. | ||
| CVE-2022-45020 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2022 | Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | ||
| CVE-2022-45019 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. | ||
| CVE-2022-45912 | Hig | 0.47 | 7.2 | 0.01 | Dec 5, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for… | ||
| CVE-2022-43553 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2022 | A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later. | ||
| CVE-2022-43548 | Hig | 0.54 | 8.1 | 0.14 | Dec 5, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests… | ||
| CVE-2022-40259 | Hig | 0.54 | 8.3 | 0.01 | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability | ||
| CVE-2022-40242 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability | ||
| CVE-2022-35259 | Hig | 0.51 | 7.8 | 0.01 | Dec 5, 2022 | XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges. | ||
| CVE-2022-35258 | Hig | 0.49 | 7.5 | 0.03 | Dec 5, 2022 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust… | ||
| CVE-2022-35254 | Hig | 0.49 | 7.5 | 0.03 | Dec 5, 2022 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust… | ||
| CVE-2022-30122 | Hig | 0.49 | 7.5 | 0.02 | Dec 5, 2022 | A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack. | ||
| CVE-2022-2827 | Hig | 0.49 | 7.5 | 0.02 | Dec 5, 2022 | AMI MegaRAC User Enumeration Vulnerability | ||
| CVE-2022-37783 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site… | ||
| CVE-2022-37325 | Hig | 0.42 | 7.5 | 0.01 | Dec 5, 2022 | In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash. | ||
| CVE-2022-45771 | Hig | 0.57 | 8.8 | 0.02 | Dec 5, 2022 | An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file. | ||
| CVE-2022-4292 | Hig | 0.00 | 7.8 | 0.01 | Dec 5, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. | ||
| CVE-2022-3907 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options. | ||
| CVE-2022-3858 | Hig | 0.47 | 7.2 | 0.01 | Dec 5, 2022 | The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as… | ||
| CVE-2022-3856 | Hig | 0.47 | 7.2 | 0.01 | Dec 5, 2022 | The Comic Book Management System WordPress plugin before 2.2.0 does not sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin. | ||
| CVE-2022-3846 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable. | ||
| CVE-2022-3694 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account. | ||
| CVE-2022-3249 | Hig | 0.47 | 7.2 | 0.01 | Dec 5, 2022 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks | ||
| CVE-2022-1540 | Hig | 0.47 | 7.2 | 0.01 | Dec 5, 2022 | The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE. | ||
| CVE-2022-45313 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2022 | Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message. | ||
| CVE-2022-43484 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2022 | TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The… | ||
| CVE-2022-43470 | Hig | 0.47 | 7.3 | 0.00 | Dec 5, 2022 | Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3.5 and earlier, and +F FS040W software versions v1.4.1 and earlier allows an adjacent attacker to… | ||
| CVE-2022-41777 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash. | ||
| CVE-2022-35507 | Hig | 0.46 | 7.1 | 0.01 | Dec 4, 2022 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects… | ||
| CVE-2022-46413 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal. | ||
| CVE-2022-46412 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands. | ||
| CVE-2022-46411 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges. | ||
| CVE-2022-46410 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands. |
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.51cvss 7.8epss 0.00
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
- risk 0.46cvss 8.1epss 0.03
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS…
- risk 0.46cvss 8.1epss 0.05
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes…
- risk 0.48cvss 7.3epss 0.01
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.
- risk 0.51cvss 7.8epss 0.00
GPAC MP4box v2.0.0 was discovered to contain a stack overflow in the smil_parse_time_list parameter at /scenegraph/svg_attributes.c.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive Information.
- risk 0.53cvss 8.1epss 0.01
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
- risk 0.49cvss 7.5epss 0.01
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
- risk 0.57cvss 8.8epss 0.01
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
- risk 0.49cvss 7.5epss 0.01
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for…
- risk 0.57cvss 8.8epss 0.01
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with an operator account to run arbitrary administrator commands.This vulnerability is fixed in Version 2.0.9-hotfix.5 and later.
- risk 0.54cvss 8.1epss 0.14
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests…
- risk 0.54cvss 8.3epss 0.01
MegaRAC Default Credentials Vulnerability
- risk 0.49cvss 7.5epss 0.01
MegaRAC Default Credentials Vulnerability
- risk 0.51cvss 7.8epss 0.01
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.
- risk 0.49cvss 7.5epss 0.03
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…
- risk 0.49cvss 7.5epss 0.03
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…
- risk 0.49cvss 7.5epss 0.02
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
- risk 0.49cvss 7.5epss 0.02
AMI MegaRAC User Enumeration Vulnerability
- risk 0.49cvss 7.5epss 0.01
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site…
- risk 0.42cvss 7.5epss 0.01
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
- risk 0.57cvss 8.8epss 0.02
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
- risk 0.49cvss 7.5epss 0.01
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.
- risk 0.47cvss 7.2epss 0.01
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as…
- risk 0.47cvss 7.2epss 0.01
The Comic Book Management System WordPress plugin before 2.2.0 does not sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
- risk 0.49cvss 7.5epss 0.01
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notification ID is brute-forceable.
- risk 0.49cvss 7.5epss 0.01
The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator's account.
- risk 0.47cvss 7.2epss 0.01
The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks
- risk 0.47cvss 7.2epss 0.01
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
- risk 0.57cvss 8.8epss 0.01
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message.
- risk 0.51cvss 7.8epss 0.00
TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The…
- risk 0.47cvss 7.3epss 0.00
Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3.5 and earlier, and +F FS040W software versions v1.4.1 and earlier allows an adjacent attacker to…
- risk 0.49cvss 7.5epss 0.01
Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash.
- risk 0.46cvss 7.1epss 0.01
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.