Vulnerabilities > Airspan > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-16 | CVE-2022-36308 | Insufficiently Protected Credentials vulnerability in Airspan Airvelocity 1500 Firmware 15.18.00.2511/9.3.0.01249 Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. | 9.1 |
2022-08-08 | CVE-2022-36264 | Unrestricted Upload of File with Dangerous Type vulnerability in Airspan Airspot 5410 Firmware 0.3.4.14 In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. | 9.1 |
2022-08-08 | CVE-2022-36267 | Unspecified vulnerability in Airspan Airspot 5410 Firmware 0.3.4.14 In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. | 9.8 |
2022-02-18 | CVE-2022-21141 | Incorrect Authorization vulnerability in Airspan products MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. | 9.8 |
2022-02-18 | CVE-2022-21143 | OS Command Injection vulnerability in Airspan products MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands. | 9.8 |
2022-02-18 | CVE-2022-21196 | Unspecified vulnerability in Airspan products MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. | 9.8 |
2022-02-18 | CVE-2022-21215 | Server-Side Request Forgery (SSRF) vulnerability in Airspan products This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. | 9.8 |