Vulnerabilities > Enterasys

DATE CVE VULNERABILITY TITLE RISK
2014-01-23 CVE-2013-7312 Unspecified vulnerability in Enterasys products
The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
5.4
2012-10-25 CVE-2011-5227 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Enterasys Netsight
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1.0.80 allows remote attackers to execute arbitrary code via a long PRIO field in a message to UDP port 514.
network
low complexity
enterasys CWE-119
critical
10.0
2007-04-27 CVE-2007-2344 Denial-Of-Service vulnerability in Enterasys Netsight Console and Netsight Inventory Manager
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
network
low complexity
enterasys
7.8
2007-04-27 CVE-2007-2343 Remote Security vulnerability in Enterasys Netsight Console and Netsight Inventory Manager
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
network
low complexity
enterasys
7.5
2005-06-16 CVE-2005-2027 Information Disclosure vulnerability in Vertical Horizon VH-2402S 2.05.00/2.05.08.01/2.05.09.07
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.
network
low complexity
enterasys
5.0
2005-06-16 CVE-2005-2026 Remote Security vulnerability in Vertical Horizon VH-2402S 2.05.00/2.05.08.01/2.05.09.07
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.
network
low complexity
enterasys
7.5
2004-08-06 CVE-2004-0674 Denial Of Service vulnerability in Enterasys Xsr-1805, Xsr-1850 and Xsr-3000
Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.
network
low complexity
enterasys
5.0
2003-04-02 CVE-2002-1501 Denial Of Service vulnerability in Enterasys SSR8000 SmartSwitch Port Scan
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
network
low complexity
enterasys
5.0
2001-10-30 CVE-2001-0669 Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.
network
low complexity
cisco iss snort enterasys
7.5