Netapp E-Series Santricity Os Controller vulnerabilities
240 known vulnerabilities affecting netapp/e-series_santricity_os_controller.
Total CVEs
240
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL31HIGH57MEDIUM107LOW45
Vulnerabilities
Page 9 of 12
CVE-2019-12261CRITICALCVSS 9.8≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12261 [CRITICAL] CWE-120 CVE-2019-12261: Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4).
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
nvd
CVE-2019-12260CRITICALCVSS 9.8≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12260 [CRITICAL] CWE-120 CVE-2019-12260: Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
nvd
CVE-2019-12257HIGHCVSS 8.8≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12257 [HIGH] CWE-120 CVE-2019-12257: Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an I
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
nvd
CVE-2019-12263HIGHCVSS 8.1≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12263 [HIGH] CWE-362 CVE-2019-12263: Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
nvd
CVE-2019-12258HIGHCVSS 7.5PoC≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12258 [HIGH] CWE-384 CVE-2019-12258: Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET securi
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
nvd
CVE-2019-12265MEDIUMCVSS 5.3≥ 8.00, ≤ 8.40.50.002019-08-09
CVE-2019-12265 [MEDIUM] CWE-401 CVE-2019-12265: Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client compon
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
nvd
CVE-2019-13272HIGHCVSS 7.8KEVPoC≥ 11.0.0, ≤ 11.60.32019-07-17
CVE-2019-13272 [HIGH] CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the cr
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing co
nvd
CVE-2019-13115HIGHCVSS 8.1≥ 11.0.0, ≤ 11.70.12019-07-16
CVE-2019-13115 [HIGH] CWE-125 CVE-2019-13115: In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has a
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client sy
nvd
CVE-2019-13118MEDIUMCVSS 5.3≥ 11.0, ≤ 11.50.22019-07-01
CVE-2019-13118 [MEDIUM] CWE-843 CVE-2019-13118: In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
nvd
CVE-2019-11068CRITICALCVSS 9.8≥ 11.0, ≤ 11.70.22019-04-10
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
nvd
CVE-2018-18314CRITICALCVSS 9.8≥ 11.0, ≤ 11.402018-12-07
CVE-2018-18314 [CRITICAL] CWE-119 CVE-2018-18314: Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid writ
Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2018-18313CRITICALCVSS 9.1≥ 11.0, ≤ 11.402018-12-07
CVE-2018-18313 [CRITICAL] CWE-125 CVE-2018-18313: Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure
Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
nvd
CVE-2018-18312CRITICALCVSS 9.8≥ 11.0, ≤ 11.402018-12-05
CVE-2018-18312 [CRITICAL] CWE-119 CVE-2018-18312: Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression t
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2018-18066HIGHCVSS 7.5≥ 11.0, ≤ 11.52018-10-08
CVE-2018-18066 [HIGH] CWE-476 CVE-2018-18066: snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
nvd
CVE-2018-18065MEDIUMCVSS 6.5PoC≥ 11.0, ≤ 11.52018-10-08
CVE-2018-18065 [MEDIUM] CWE-476 CVE-2018-18065: _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
nvd
CVE-2018-5492CRITICALCVSS 9.8≥ 11.0, ≤ 11.402018-10-04
CVE-2018-5492 [CRITICAL] CWE-20 CVE-2018-5492: NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to
NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remote code execution.
nvd
CVE-2018-2938CRITICALCVSS 9.0≥ 11.0, ≤ 11.70.12018-07-18
CVE-2018-2938 [CRITICAL] CVE-2018-2938: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impac
nvd
CVE-2018-2941HIGHCVSS 8.3≥ 11.0, ≤ 11.70.12018-07-18
CVE-2018-2941 [HIGH] CVE-2018-2941: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the a
nvd
CVE-2018-2942HIGHCVSS 8.3≥ 11.0, ≤ 11.70.12018-07-18
CVE-2018-2942 [HIGH] CVE-2018-2942: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported vers
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the att
nvd
CVE-2018-2964HIGHCVSS 8.3≥ 11.0, ≤ 11.70.12018-07-18
CVE-2018-2964 [HIGH] CVE-2018-2964: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versi
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the att
nvd