Vulnerabilities (CVE)

Filtered by vendor Secureauth Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-31800 2 Fedoraproject, Secureauth 2 Fedora, Impacket 2024-02-28 7.5 HIGH 9.8 CRITICAL
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
CVE-2020-9437 1 Secureauth 1 Secureauth Identity Provider 2024-02-28 3.5 LOW 4.8 MEDIUM
SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.