Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Airvelocity 1500 Firmware HIGH 8.8
CVE-2022-36312

Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelo…

Mitigation only
Fix from $1,950 2022-08-16
Airvelocity 1500 Firmware CRITICAL 9.1
CVE-2022-36308

Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 cr…

Fix: after 15.18.00.2511
Fix from $2,300 2022-08-16
Airvelocity 1500 Firmware HIGH 8.8
CVE-2022-36309EPSS 24%

Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the reco…

Fix: after 15.18.00.2511
Fix from $1,950 2022-08-16
Airvelocity 1500 Firmware HIGH 8.8
CVE-2022-36310

Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP…

Fix: after 15.18.00.2511
Fix from $1,950 2022-08-16
Airvelocity 1500 Firmware MEDIUM 6.8
CVE-2022-36307

The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software versio…

Fix: after 15.18.00.2511
Fix from $1,600 2022-08-16
Airvelocity 1500 Firmware MEDIUM 6.5
CVE-2022-36306

An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server bina…

Fix: after 15.18.00.2511
Fix from $1,600 2022-08-16
Airvelocity 1500 Firmware MEDIUM 6.1
CVE-2022-36311

Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in the eNodeB'…

Fix: 15.18.00.2511+
Fix from $1,600 2022-08-16
Airspot 5410 Firmware CRITICAL 9.8
CVE-2022-36267EPSS 54%

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can…

Fix: after 0.3.4.1-4
Fix from $2,300 2022-08-08
Airspot 5410 Firmware CRITICAL 9.1
CVE-2022-36264

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriti…

Fix: after 0.3.4.1-4
Fix from $2,300 2022-08-08
Airspot 5410 Firmware HIGH 7.2
CVE-2022-36265

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firm…

Fix: after 0.3.4.1-4
Fix from $1,950 2022-08-08
Airspot 5410 Firmware MEDIUM 6.1
CVE-2022-36266

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not …

Fix: after 0.3.4.1-4
Fix from $1,600 2022-08-08
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21141

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21143

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21196

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21215

This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only acce…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Mimosa Management Platform HIGH 7.5
CVE-2022-21176

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $1,950 2022-02-18
Mimosa Management Platform MEDIUM 6.5
CVE-2022-21800

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses…

Fix: 1.0.3 / 2.5.4.1+
Fix from $1,600 2022-02-18
Mimosa Management Platform HIGH 7.5
CVE-2022-0138

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has …

Fix: 1.0.3 / 2.5.4.1+
Fix from $1,950 2022-02-18
Base Station Distribution Unit HIGH 7.5
CVE-2008-1542

Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain administr…

No fix yet
Fix from $1,950 2008-03-28
Prost Web Management HIGH 7.5
CVE-2008-1543

The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and password, which…

Mitigation only
Fix from $1,950 2008-03-28
Wimax Prost HIGH 10.0
CVE-2008-1262EPSS 9%

The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remot…

No fix yet
Fix from $1,950 2008-03-10