Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opennds opennds vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-38317
An issue exists in OpenNDS prior to 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Opennds Opennds
9.8
CVSSv3
CVE-2023-38318
An issue exists in OpenNDS prior to 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Opennds Opennds
9.8
CVSSv3
CVE-2023-38319
An issue exists in OpenNDS prior to 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Opennds Opennds
9.8
CVSSv3
CVE-2023-38323
An issue exists in OpenNDS prior to 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Opennds Opennds
9.8
CVSSv3
CVE-2023-41101
An issue exists in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and previous versions, and to a heap-based buffer o...
Opennds Opennds
9.8
CVSSv3
CVE-2023-38316
An issue exists in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests.
Opennds Captive Portal
7.5
CVSSv3
CVE-2023-38321
OpenNDS, as used in Sierra Wireless ALEOS prior to 4.17.0.12 and other products, allows remote malicious users to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string par...
Sierrawireless Aleos
7.5
CVSSv3
CVE-2023-41102
An issue exists in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory.
Opennds Opennds
7.5
CVSSv3
CVE-2023-38313
An issue exists in OpenNDS Captive Portal prior to 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Serv...
Opennds Captive Portal
7.5
CVSSv3
CVE-2023-38315
An issue exists in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-...
Opennds Captive Portal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »