CWE-696

CWE-696 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-696, highest CVSS first.

  1. HIGH 7.4CVE-2026-73446

    On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4.3CVE-2026-93330

    Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-93304public PoC

    A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished agai…

    AI risk analysis on Exploit-DB.ai →