Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.0F5

Medium [CVE-2023-3470] Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account

Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP systems, all Guests share the same deterministic password, allowing those with TMSH access on one Guest to access keys of a different Guest. The following BIG-IP hardware platforms are affected: 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F. The BIG-IP rSeries r5920-DF and r10920-DF are not affected, nor does the issue affect software FIPS implementations or network HSM configurations. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-3470
BIG-IP
Aug 2, 2023
Medium5.4F5

Medium [CVE-2023-38423] cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38423
BIG-IP
Aug 2, 2023
Medium4.3F5

Medium [CVE-2023-38419] authenticated attacker with guest privileges or higher

An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38419
Unclassified
Aug 2, 2023
Medium4.4F5

Medium [CVE-2023-36494] F5OS: Audit logs on F5OS-A may contain undisclosed sensitive information.

Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-36494
F5OS / Distributed Cloud
Aug 2, 2023
Medium4.3Splunk

Medium [CVE-2023-32717] On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an…

On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.

CVE-2023-32717
Splunk EnterpriseSplunk Cloud Platform
Jun 1, 2023
Medium6.5Splunk

Medium [CVE-2023-32716] In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk daemon.

CVE-2023-32716
Splunk EnterpriseSplunk Cloud Platform
Jun 1, 2023
Medium4.7Splunk

Medium [CVE-2023-32715] In the Splunk App for Lookup File Editing versions below 4.0.1, a user

In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes that code to run on the user’s machine. The app itself does not contain the potentially malicious JavaScript code. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser, and requires additional user interaction to trigger. The attacker cannot exploit the vulnerability at will.

CVE-2023-32715
Unclassified
Jun 1, 2023
Medium5.4Splunk

Medium [CVE-2019-8331 +1] In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, a Splunk dashboard view lets a low-privileged user exploit a vulnerability in the Bootstrap web framework (CVE-2019-8331) and build a stored cross-site scripting (XSS) payload.

CVE-2019-8331CVE-2023-32711
Splunk Enterprise
Jun 1, 2023
Medium4.8Splunk

Medium [CVE-2023-32710] In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a…

In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can perform an unauthorized transfer of data from a search using the ‘copyresults’ command if they know the search ID (SID) of a search job that has recently run.

CVE-2023-32710
Splunk EnterpriseSplunk Cloud Platform
Jun 1, 2023
Medium4.3Splunk

Medium [CVE-2023-32709] Splunk Enterprise: In Splunk Enterprise versions below 9.0.5, 8.2.11.

In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user who holds the ‘user’ role can see the hashed version of the initial user name and password for the Splunk instance by using the ‘rest’ SPL command against the ‘conf-user-seed’ REST endpoint.

CVE-2023-32709
Splunk EnterpriseSplunk Cloud Platform
Jun 1, 2023
Medium6.5Atlassian

Medium [CVE-2023-22504] Affected versions of Atlassian Confluence Server

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.

CVE-2023-22504
Confluence
May 25, 2023
Medium5.4F5

Medium [CVE-2023-29240] authenticated attacker granted a Viewer or Auditor role on a BIG-IQ

An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-29240
BIG-IQ
May 3, 2023
Medium4.3F5

Medium [CVE-2023-28406] directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may

A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with.xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-28406
BIG-IP
May 3, 2023
Medium5.3F5

Medium [CVE-2023-24594] When an SSL profile is configured on a Virtual Server, undisclosed traffic

When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-24594
Unclassified
May 3, 2023
Medium5.9F5

Medium [CVE-2023-22372] In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows…

In the pre connection stage, an improper enforcement of message integrity vulnerability exists in BIG-IP Edge Client for Windows and Mac OS. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-22372
BIG-IP
May 3, 2023
Medium6.5Sophos

Medium [CVE-2020-36692] reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4

A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.

CVE-2020-36692
Unclassified
Apr 4, 2023
Medium6.6QNAP

Medium [CVE-2023-23355] QTS: OS command injection vulnerability has been reported to affect QNAP operating systems.

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors. QES is not affected. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h5.0.1.2348 build 20230324 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2023-23355
QTSQuTS hero
Mar 29, 2023
Medium5.5Sophos

Medium [CVE-2022-48310] Sophos Connect: information disclosure vulnerability

An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-48310
Sophos Mobile / Connect
Mar 1, 2023
Medium4.3Sophos

Medium [CVE-2022-48309] CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older…

A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.

CVE-2022-48309
Sophos Mobile / Connect
Mar 1, 2023
Medium4.8Splunk

Medium [CVE-2023-22943] In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to…

In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the REST API Modular Input incorrectly revert to using HTTP to connect after a failure to connect over HTTPS occurs.

CVE-2023-22943
Unclassified
Feb 14, 2023