← Back

Contivity

contivity

Vendor: Nortel • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nortel
2Contivity
Vpn Router 5000
Apr 23, 2026
Apr 27, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers...Show more
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests.Show less
1Nortel
3Contivity
Vpn Router 5000Vpn Router Portfolio
Apr 23, 2026
Apr 27, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP te...Show more
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.Show less
1Nortel
1Contivity
Apr 16, 2026
Aug 16, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the Fil...Show more
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box.Show less
1Nortel
9Contivity
Vpn Router 1010Vpn Router 1050+6 more
Apr 16, 2026
May 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.
1Nortel
1Contivity
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.
1Nortel
1Contivity
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.
1Nortel
1Contivity
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition tha...Show more
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.Show less
1Nortel
1Contivity
Apr 16, 2026
Jan 17, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.
1Nortel
1Contivity
Apr 16, 2026
Jan 17, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.