kratosdefense CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

kratosdefense vulnerability overview

Aggregates CVE and security vulnerability intelligence across all kratosdefense-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk command injection and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-36670 A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device. [email protected] 9.8 0.31% 2023-07-18 2024-11-21
CVE-2023-36669 Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU. [email protected] 9.8 0.27% 2023-07-18 2024-11-21
CVE-2022-38156 A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Linux commands as the root user. [email protected] 7.2 0.35% 2023-06-12 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence