Vulnerabilities > Alliedtelesis

DATE CVE VULNERABILITY TITLE RISK
2019-11-29 CVE-2019-18922 Path Traversal vulnerability in Alliedtelesis At-Gs950/8 Firmware
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request.
network
low complexity
alliedtelesis CWE-22
7.5
2019-05-07 CVE-2018-20503 Cross-site Scripting vulnerability in Alliedtelesis 8100L/8 Firmware
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
network
low complexity
alliedtelesis CWE-79
6.1