Vulnerabilities (CVE)

Filtered by vendor Noviflow Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13122 1 Noviflow 1 Noviware 2020-08-21 8.0 HIGH 8.8 HIGH
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only user (monitoring group) or admin to execute commands on the operating system.