NetscoutCVEs & Vulnerabilities

41 CVEs affecting Netscout products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

ngeniusone 36ngeniuspulse 3sensor4-r1s1w1-e 1sensor4-r2s1-e 1sensor4-r2s1-i 1sensor6-r1s0w1-e 1sensor6-r2s1-e 1sensor6-r2s1-i 1
CVE-2025-32986HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.

26 Apr 2025
7.5
CVSS
CVE-2025-32985CRITICAL

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

26 Apr 2025
9.8
CVSS
CVE-2025-32984MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

26 Apr 2025
6.1
CVSS
CVE-2025-32983HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

26 Apr 2025
7.5
CVSS
CVE-2025-32982HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

26 Apr 2025
7.5
CVSS
CVE-2025-32981HIGH

NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

26 Apr 2025
7.1
CVSS
CVE-2025-32979MEDIUM

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

26 Apr 2025
6.5
CVSS
CVE-2023-27000MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).

9 Jan 2024
6.1
CVSS
CVE-2023-26999CRITICAL

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

9 Jan 2024
9.8
CVSS
CVE-2023-26998MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

9 Jan 2024
5.4
CVSS
CVE-2023-41905MEDIUM

NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.

7 Dec 2023
5.4
CVSS
CVE-2023-41172MEDIUM

NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).

7 Dec 2023
5.4
CVSS
CVE-2023-41171MEDIUM

NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).

7 Dec 2023
5.4
CVSS
CVE-2023-41170MEDIUM

NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.

7 Dec 2023
6.1
CVSS
CVE-2023-41169MEDIUM

NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).

7 Dec 2023
5.4
CVSS
CVE-2023-41168MEDIUM

NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).

7 Dec 2023
5.4
CVSS
CVE-2023-40302CRITICAL

NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability

7 Dec 2023
9.1
CVSS
CVE-2023-40301CRITICAL

NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

7 Dec 2023
9.8
CVSS
CVE-2023-40300CRITICAL

NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

7 Dec 2023
9.8
CVSS
CVE-2022-44718LOW

An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.

27 Jan 2023
3.5
CVSS
CVE-2022-44717LOW

An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.

27 Jan 2023
3.1
CVSS
CVE-2022-44715HIGH

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

27 Jan 2023
8.8
CVSS
CVE-2022-44029MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6.

27 Jan 2023
6.1
CVSS
CVE-2022-44028MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6.

27 Jan 2023
6.1
CVSS
CVE-2022-44027MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6.

27 Jan 2023
6.1
CVSS
CVE-2022-44026MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6.

27 Jan 2023
6.1
CVSS
CVE-2022-44025MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6.

27 Jan 2023
6.1
CVSS
CVE-2022-44024MEDIUM

An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6.

27 Jan 2023
6.1
CVSS
CVE-2021-45983CRITICAL

NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.

2 Jun 2022
9.8
CVSS
CVE-2021-45982HIGH

NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.

2 Jun 2022
8.8
CVSS
CVE-2021-45981CRITICAL

NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

2 Jun 2022
9.8
CVSS
CVE-2021-35205MEDIUM

NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.

30 Sep 2021
5.4
CVSS
CVE-2021-35204MEDIUM

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.

30 Sep 2021
5.4
CVSS
CVE-2021-35203MEDIUM

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.

30 Sep 2021
5.7
CVSS
CVE-2021-35202MEDIUM

NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.

30 Sep 2021
4.3
CVSS
CVE-2021-35201MEDIUM

NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.

30 Sep 2021
6.5
CVSS
CVE-2021-35200MEDIUM

NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService.

30 Sep 2021
4.8
CVSS
CVE-2021-35199MEDIUM

NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.

30 Sep 2021
5.4
CVSS
CVE-2021-35198MEDIUM

NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.

30 Sep 2021
5.4
CVSS
CVE-2020-28251HIGH

NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.

3 Dec 2020
8.1
CVSS
CVE-2008-6701HIGH

NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request.

11 Apr 2009
7.5
CVSS
← PrevPage 1 / 1Next →
Netscout CVEs & Vulnerabilities — 41 Tracked