Filtered by vendor H3c Subscriptions
Filtered by product Ssl Vpn Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-50800 1 H3c 1 Ssl Vpn 2026-01-05 7.5 High
H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response messages to distinguish between existing and non-existing accounts.
CVE-2022-35416 1 H3c 1 Ssl Vpn 2024-11-21 6.1 Medium
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.