Vulnerabilities > Garrettcom

DATE CVE VULNERABILITY TITLE RISK
2015-08-04 CVE-2015-3961 Resource Management Errors vulnerability in Garrettcom Magnum 10K Firmware and Magnum 6K Firmware
The web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allows remote authenticated users to cause a denial of service (memory corruption and reboot) via a crafted URL.
3.5
2015-08-04 CVE-2015-3960 Cryptographic Issues vulnerability in Garrettcom Magnum 10K Firmware and Magnum 6K Firmware
The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys and certificates across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms for HTTPS sessions by leveraging knowledge of a private key from another installation.
4.3
2015-08-04 CVE-2015-3959 Local Security Bypass vulnerability in GarrettCom Magnum 6K and 10K Switches Hardcoded Credentials
The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password.
local
low complexity
garrettcom
7.2
2015-08-04 CVE-2015-3942 Cross-site Scripting vulnerability in Garrettcom Magnum 10K Firmware and Magnum 6K Firmware
Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
garrettcom CWE-79
4.3
2012-09-04 CVE-2012-3014 Credentials Management vulnerability in Garrettcom products
The Management Software application in GarrettCom Magnum MNS-6K before 4.4.0, and 14.x before 14.4.0, has a hardcoded password for an administrative account, which allows local users to gain privileges via unspecified vectors.
low complexity
garrettcom CWE-255
7.7