VYPR

Unity Edgeconnect Sd Wan Firmware

by Silver Peak

CVEs (7)

  • CVE-2019-16102CriSep 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.

  • CVE-2019-16099HigSep 8, 2019
    risk 0.57cvss 8.8epss 0.01

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

  • CVE-2019-16100HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.02

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.

  • CVE-2019-16103HigSep 8, 2019
    risk 0.47cvss 7.2epss 0.02

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.

  • CVE-2019-16104MedSep 8, 2019
    risk 0.40cvss 6.1epss 0.01

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

  • CVE-2019-16101MedSep 8, 2019
    risk 0.35cvss 5.3epss 0.01

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

  • CVE-2019-16105MedSep 8, 2019
    risk 0.32cvss 4.9epss 0.02

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.