Логотип exploitDog
bind:CVE-2017-12787
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-12787

Количество 3

Количество 3

nvd логотип

CVE-2017-12787

больше 8 лет назад

A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-5gx4-r4vg-49w6

больше 3 лет назад

A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2017-01997

больше 8 лет назад

Уязвимость компонента ACL операционной системы NoviWare, вызванная переполнением буфера на стеке, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-12787

A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.

CVSS3: 9.8
34%
Средний
больше 8 лет назад
github логотип
GHSA-5gx4-r4vg-49w6

A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.

CVSS3: 9.8
34%
Средний
больше 3 лет назад
fstec логотип
BDU:2017-01997

Уязвимость компонента ACL операционной системы NoviWare, вызванная переполнением буфера на стеке, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
34%
Средний
больше 8 лет назад

Уязвимостей на страницу