CVE's
Security Advisory ZPE-NG-2024-003
Advisory ID: ZPE-NG-2024-003 First Published: Oct 01, 2024 CVE ID: CVE-2023-51767 (details on NIST.gov) CVSSv3 Base Score: 7.0 (High) Summary OpenSSH, when common types of DRAM are used, might allow rowhammer attacks (for authentication bypass) ...
Security Advisory ZPE-NG-2024-002
Advisory ID: ZPE-NG-2024-002 First Published: August 9, 2024 CVE ID: CVE-2024-37407 (details on NIST.gov) CVSSv3 Score: 9.1 (Critical) CVE ID: CVE-2024-26256 (details on NIST.gov) CVSSv3 Base Score: 7.8 (High) Summary Libarchive allows out-of-bounds ...
Security Advisory ZPE-NG-2024-001
Advisory ID: ZPE-NG-2024-001 First Published: July 8, 2024 CVE ID: CVE-2024-6387 (details on NIST.gov) CVSSv3 Score: 8.1 (High) Summary If a client does not authenticate within LoginGraceTime seconds, by default three minutes, then sshd's SIGALRM ...
Security Advisory ZPE-NG-2023-003
Advisory ID: ZPE-NG-2023-003 First Published: January 02, 2024 CVE ID: CVE-2004-0230 CVSSv2 Score: 5.0 (Medium) Summary TCP connections with large window size may be susceptible to be disconnected by repeatedly injecting TCP reset packets, especially ...
Security Advisory ZPE-NG-2023-002
Advisory ID: ZPE-NG-2023-002 First Published: October 13, 2023 CVE ID: CVE-2023-44037 CVSSv3 Score: 7.5 (High) Summary Password sent as username when remote authentication is configured with method TACACS+ and TACACS+ minor version is 0. This only ...
Security Advisory ZPE-NG-2023-001
Advisory ID: ZPE-NG-2023-001 First Published: October 27, 2023 CVE ID: CVE-2023-43322 CVSSv3 Score: 8.8 (High) Summary Command injection [CWE-77] is possible in the following API endpoints: /v1/system/toolkit/files/upload ...