24 vulnerabilidades · Networking · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-3400
🔥 KEV PAN-OS Networking Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-77 45 PoCs

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

CVE-2024-20419
Cisco Smart Software Manager On-Prem Web Networking ⚡ nuclei
10.0
CRITICAL
EPSS
91.4%
2024 CWE-620 2 PoCs

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.

CVE-2024-9463
🔥 KEV Expedition Web Networking ⚡ nuclei
9.9
CRITICAL
EPSS
94.2%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-57045
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
66.8%
2024 0 PoCs

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

CVE-2024-9643
F3x36 Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
26.2%
2024 CWE-489 1 PoC

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge of the credentials can gain administrative access via crafted HTTP requests. This issue appears similar to CVE-2023-32645.

CVE-2024-57049
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
34.6%
2024 1 PoC

A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables."

CVE-2024-32238
Software Genérico Networking ⚡ nuclei
9.8
CRITICAL
EPSS
88.5%
2024 1 PoC

H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

CVE-2024-20439
🔥 KEV Cisco Smart License Utility Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
87.1%
2024 CWE-912 0 PoCs

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.

CVE-2024-5910
🔥 KEV Expedition Networking ⚡ nuclei
9.3
CRITICAL
EPSS
91.0%
2024 CWE-306 1 PoC

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

CVE-2024-0012
🔥 KEV Cloud NGFW Web Networking Cloud ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-306 13 PoCs

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice d

CVE-2024-9465
🔥 KEV Expedition Web Networking Database ⚡ nuclei
9.2
CRITICAL
EPSS
94.3%
2024 CWE-89 5 PoCs

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVE-2024-57046
Software Genérico Networking ⚡ nuclei
8.8
HIGH
EPSS
46.7%
2024 1 PoC

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

CVE-2024-48248
🔥 KEV Backup & Replication Director Networking ⚡ nuclei
8.6
HIGH
EPSS
94.0%
2024 CWE-36 3 PoCs

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

CVE-2024-24919
🔥 KEV Check Point Quantum Gateway, Spark Gateway and CloudGuard Network Networking Cloud ⚡ nuclei
8.6
HIGH
EPSS
94.3%
2024 CWE-200 67 PoCs

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

CVE-2024-53704
🔥 KEV SonicOS Networking ⚡ nuclei
8.2
HIGH
EPSS
93.9%
2024 CWE-287 1 PoC

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVE-2024-56159
astro Web Networking ⚡ nuclei
7.8
HIGH
EPSS
8.2%
2024 CWE-219 0 PoCs

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the server code** are moved to a publicly-accessible folder. Any outside party can read them with an unauthorized HTTP GET request to the same server hosting the rest of the website. While some server files are hashed, making their access obscure, the files corresponding to the file system router (those in `src/pages`) are predictably named. For examp

CVE-2024-38816
Spring Web Networking ⚡ nuclei
7.5
HIGH
EPSS
93.9%
2024 3 PoCs

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running. Specifically, an application is vulnerable when both of the following are true: * the web application uses RouterFunctions to serve static resources * resource handling is explicitly configured with a FileSystemResource location However, malicious requests are blocked and rejecte

CVE-2024-1728
gradio-app/gradio Networking ⚡ nuclei
7.5
HIGH
EPSS
86.5%
2024 CWE-22 1 PoC

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.

CVE-2024-20440
Cisco Smart License Utility Web Networking ⚡ nuclei
7.5
HIGH
EPSS
79.0%
2024 CWE-532 0 PoCs

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

CVE-2024-3848
mlflow/mlflow Networking Cloud ⚡ nuclei
7.5
HIGH
EPSS
78.7%
2024 CWE-29 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the appl