High
CVSS: 8.1
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
Medium
CVSS: 6.5
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
Medium
CVSS: 5.0
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible…
Medium
CVSS: 6.1
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
Medium
CVSS: 6.5
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).
Medium
CVSS: 5.4
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.
Low
CVSS: 3.5
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
Medium
CVSS: 5.3
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not pr…