📦

unity_edgeconnect_sd-wan

Vendor: silver-peak

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 7 Total Indexed
Avg. EPSS 1.40% Exploit Prob.
Latest CVE CVE-2019-16105 Sep 08

Security Vulnerability Index

Page 1 / 1
4.9 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.

EPSS: 1.71%
6.1 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

EPSS: 0.82%
7.2 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.

EPSS: 1.82%
9.8 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.

EPSS: 1.54%
5.3 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

EPSS: 1.49%
7.5 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.

EPSS: 1.81%
8.8 CVSS

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

EPSS: 0.61%