321 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-25759
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

CVE-2020-16135
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.

CVE-2020-20250
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). NOTE: this is different from CVE-2020-20253 and CVE-2020-20254. All four vulnerabilities in the /nova/bin/lcdstat process are discussed in the CVE-2020-20250 github.com/cq674350529 reference.

CVE-2020-20021
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.

CVE-2020-10812
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A NULL pointer dereference exists in the function H5F_get_nrefs() located in H5Fquery.c. It allows an attacker to cause Denial of Service.

CVE-2020-15313
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.

CVE-2020-25043
Kaspersky VPN Secure Connection Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.

CVE-2020-21933
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.

CVE-2020-24104
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.

CVE-2020-21936
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.

CVE-2020-10809
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

CVE-2020-17352
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.

CVE-2020-20216
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVE-2020-24365
Software Genérico Networking
N/A
UNKNOWN
EPSS
14.2%
2020 1 PoC

An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a login is required, most routers are left with default credentials.)

CVE-2020-22079
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.

CVE-2020-36313
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.

CVE-2020-20245
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-9283
Software Genérico Networking
N/A
UNKNOWN
EPSS
18.7%
2020 2 PoCs

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

CVE-2020-25592
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
43.4%
2020 1 PoC

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

CVE-2020-11967
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”