Netscout
Netscout Ngeniusone: vulnerabilidades y CVE
Netscout Ngeniusone tiene 37 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-32986 | Alta (7.5) | 0.43% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint. |
| CVE-2025-32985 | Crítica (9.8) | 0.44% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. |
| CVE-2025-32984 | Media (6.1) | 0.25% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter. |
| CVE-2025-32983 | Alta (7.5) | 0.41% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace. |
| CVE-2025-32982 | Alta (7.5) | 0.38% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module. |
| CVE-2025-32981 | Alta (7.1) | 0.22% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File. |
| CVE-2025-32980 | Crítica (9.8) | 0.44% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration. |
| CVE-2025-32979 | Media (6.5) | 0.35% | — | 25 abr 2025 | NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users. |
| CVE-2023-27000 | Media (6.1) | 0.54% | — | 9 ene 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s). |
| CVE-2023-26999 | Crítica (9.8) | 1.1% | — | 9 ene 2024 | An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file. |
| CVE-2023-26998 | Media (5.4) | 0.51% | — | 9 ene 2024 | Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page. |
| CVE-2023-41905 | Media (5.4) | 0.39% | — | 7 dic 2023 | NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user. |
| CVE-2023-41172 | Media (5.4) | 0.39% | — | 7 dic 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). |
| CVE-2023-41171 | Media (5.4) | 0.39% | — | 7 dic 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). |
| CVE-2023-41170 | Media (6.1) | 0.41% | — | 7 dic 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. |
| CVE-2023-41169 | Media (5.4) | 0.39% | — | 7 dic 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). |
| CVE-2023-41168 | Media (5.4) | 0.39% | — | 7 dic 2023 | NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). |
| CVE-2022-44718 | Baja (3.5) | 0.32% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to… |
| CVE-2022-44717 | Baja (3.1) | 0.28% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to… |
| CVE-2022-44715 | Alta (8.8) | 0.73% | — | 27 ene 2023 | Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload. |
| CVE-2022-44029 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6. |
| CVE-2022-44028 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6. |
| CVE-2022-44027 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6. |
| CVE-2022-44026 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6. |
| CVE-2022-44025 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6. |
| CVE-2022-44024 | Media (6.1) | 0.35% | — | 27 ene 2023 | An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6. |
| CVE-2021-45983 | Crítica (9.8) | 1.4% | — | 2 jun 2022 | NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution. |
| CVE-2021-45982 | Alta (8.8) | 0.95% | — | 2 jun 2022 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. |
| CVE-2021-45981 | Crítica (9.8) | 1.1% | — | 2 jun 2022 | NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. |
| CVE-2021-35205 | Media (5.4) | 0.43% | — | 30 sept 2021 | NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector. |