3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2007-1064
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.

CVE-2014-2925
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi.

CVE-2015-0659
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers to trigger self-referential adjacencies via a crafted Autonomic Networking (AN) message, aka Bug ID CSCup62157.

CVE-2017-15291
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.

CVE-2017-7522
OpenVPN Networking
N/A
UNKNOWN
EPSS
0.5%
2017 CWE-20 1 PoC

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVE-2017-14115
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.0%
2017 1 PoC

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, which allows remote attackers to access a "Terminal shell v1.0" service, and subsequently obtain unrestricted root privileges, by establishing an SSH session and then entering certain shell metacharacters and BusyBox commands.

CVE-2017-3133
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

CVE-2015-1451
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.

CVE-2017-6640
Cisco Prime Data Center Network Manager Server Static Credential Vulnerability Networking
N/A
UNKNOWN
EPSS
53.1%
2017 CWE-264 1 PoC

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to

CVE-2017-3216
BM2022 Web Networking
N/A
UNKNOWN
EPSS
3.2%
2017 CWE-306 1 PoC

WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

CVE-2017-5329
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.

CVE-2017-14705
Software Genérico Web Networking Cloud
N/A
UNKNOWN
EPSS
4.4%
2017 1 PoC

DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication parameter is required but can be obtained by exploiting CVE-2017-14706. This affects DenyAll i-Suite LTS 5.5.0 through 5.5.12, i-Suite 5.6, Web Application Firewall 5.7, and Web Application Firewall 6.x before 6.4.1, with On Premises or AWS/Azure cloud deployments.

CVE-2014-6751
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The Grasshopper Beta (aka com.grasshopper.dialer) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2017-9024
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.1%
2017 2 PoCs

Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.

CVE-2017-11320
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2017 2 PoCs

Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router.

CVE-2017-5135
Software Genérico Networking
N/A
UNKNOWN
EPSS
22.4%
2017 1 PoC

Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D3928SL-P15-13-A386-c3420r55105-160127a could be reached by any SNMP community string from the Internet; also, you can write in the MIB because it provides write properties, aka Stringbleed. NOTE: the string-bleed/StringBleed-CVE-2017-5135 GitHub repository is not a valid reference as of 2017-04-27; it contains Trojan horse code purported to exploit this vulnerability.

CVE-2017-15895
Synology Router Manager (SRM) Networking
N/A
UNKNOWN
EPSS
0.3%
2017 CWE-22 1 PoC

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.

CVE-2015-4325
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering the restart of a process by the root account, aka Bug ID CSCuv12272.

CVE-2017-16902
Software Genérico Networking
N/A
UNKNOWN
EPSS
18.3%
2017 1 PoC

On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.

CVE-2017-16083
node-simple-router node module Networking
N/A
UNKNOWN
EPSS
0.6%
2017 CWE-22 1 PoC

node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.