VendorsNetscoutngeniusoneall versions
Vulnerabilities

Netscout Ngeniusone

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2021-45983
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
Published 2022-06-02 · Modified
9.8EPSS 0.014
CVE-2021-45981
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
Published 2022-06-02 · Modified
9.8EPSS 0.011
CVE-2023-26999
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.
Published 2024-01-09 · Modified
9.8EPSS 0.011
CVE-2025-32985
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
Published 2025-04-25 · Analyzed
9.8EPSS 0.004
CVE-2021-45982
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
Published 2022-06-02 · Modified
8.8EPSS 0.010
CVE-2022-44715
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
Published 2023-01-27 · Modified
8.8EPSS 0.007
CVE-2025-32986
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
Published 2025-04-25 · Analyzed
7.5EPSS 0.004
CVE-2025-32983
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
Published 2025-04-25 · Analyzed
7.5EPSS 0.004
CVE-2025-32982
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
Published 2025-04-25 · Analyzed
7.5EPSS 0.004
CVE-2022-44026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6.
Published 2023-01-27 · Modified
7.1EPSS 0.004
CVE-2025-32981
NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.
Published 2025-04-25 · Analyzed
7.1EPSS 0.002
CVE-2021-35201
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
Published 2021-09-30 · Modified
6.5EPSS 0.010
CVE-2025-32979
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
Published 2025-04-25 · Analyzed
6.5EPSS 0.003
CVE-2023-27000
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).
Published 2024-01-09 · Modified
6.1EPSS 0.005
CVE-2023-41170
NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.
Published 2023-12-07 · Modified
6.1EPSS 0.004
CVE-2022-44027
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6.
Published 2023-01-27 · Modified
6.1EPSS 0.004
CVE-2022-44028
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6.
Published 2023-01-27 · Modified
6.1EPSS 0.004
CVE-2022-44029
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6.
Published 2023-01-27 · Modified
6.1EPSS 0.004
CVE-2022-44025
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6.
Published 2023-01-27 · Modified
6.1EPSS 0.004
CVE-2022-44024
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6.
Published 2023-01-27 · Modified
6.1EPSS 0.004
CVE-2025-32984
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.
Published 2025-04-25 · Analyzed
6.1EPSS 0.003
CVE-2021-35203
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
Published 2021-09-30 · Modified
5.7EPSS 0.007
CVE-2023-26998
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.
Published 2024-01-09 · Modified
5.4EPSS 0.005
CVE-2021-35199
NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.
Published 2021-09-30 · Modified
5.4EPSS 0.005
CVE-2021-35204
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.
Published 2021-09-30 · Modified
5.4EPSS 0.005
CVE-2021-35198
NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.
Published 2021-09-30 · Modified
5.4EPSS 0.005
CVE-2021-35205
NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
Published 2021-09-30 · Modified
5.4EPSS 0.004
CVE-2023-41168
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2023-41169
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2023-41171
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2023-41172
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2023-41905
NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2021-35200
NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService.
Published 2021-09-30 · Modified
4.8EPSS 0.005
CVE-2021-35202
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
Published 2021-09-30 · Modified
4.3EPSS 0.007
CVE-2022-44718
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
Published 2023-01-27 · Modified
3.5EPSS 0.003
CVE-2022-44717
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.
Published 2023-01-27 · Modified
3.1EPSS 0.003