VendorsA10 Networksadvanced_core_operating_systemall versions
Vulnerabilities

A10 Networks Advanced Core Operating System (ACOS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-24384
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.
Published 2020-11-10 · Modified
10.0EPSS 0.035
CVE-2024-30368
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability
Published 2024-06-06 · Modified
8.8EPSS 0.030
CVE-2023-42130
A10 Thunder ADC FileMgmtExport Directory Traversal Arbitrary File Read and Deletion Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.021
CVE-2018-5390
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
Published 2018-08-06 · Modified
7.8EPSS 0.737
CVE-2024-30369
A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Published 2024-06-06 · Modified
7.8EPSS 0.003
CVE-2023-42129
A10 Thunder ADC ShowTechDownloadView Directory Traversal Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5EPSS 0.024
CVE-2016-10213
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.
Published 2017-02-08 · Modified
5.9EPSS 0.021
CVE-2014-3976
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.
Published 2014-06-05 · Modified
5.01 PoCEPSS 0.116