Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Elitecore Subscribe
Filtered by product Cyberoam Unified Threat Management
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-5050 1 Elitecore 1 Cyberoam Unified Threat Management 2017-08-28 6.0 MEDIUM N/A
SQL injection vulnerability in corporate/Controller in Elitecore Technologies Cyberoam UTM before 10.01.2 build 059 allows remote authenticated administrators to execute arbitrary SQL commands via the tableid parameter. NOTE: some of these details are obtained from third party information.
CVE-2012-3372 1 Elitecore 1 Cyberoam Unified Threat Management 2012-07-09 5.8 MEDIUM N/A
** DISPUTED ** The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of trusted root certification authorities. NOTE: the vendor disputes the significance of this issue because the appliance "does not allow import or export of the foresaid private key."