3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2007-4415
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2007 1 PoC

Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions for cvpnd.exe (Modify granted to Interactive Users), which allows local users to gain privileges via a modified cvpnd.exe.

CVE-2007-2242
Software Genérico Networking
N/A
UNKNOWN
EPSS
33.4%
2007 2 PoCs

The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two routers.

CVE-2007-1068
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.

CVE-2007-4430
Software Genérico Networking
N/A
UNKNOWN
EPSS
27.0%
2007 1 PoC

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

CVE-2014-4728
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2014 2 PoCs

The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.

CVE-2015-1570
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.

CVE-2017-11361
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.)

CVE-2017-7336
Fortinet FortiWLM Networking
N/A
UNKNOWN
EPSS
0.9%
2017 1 PoC

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

CVE-2019-12549
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.

CVE-2020-15317
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.

CVE-2017-5633
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2017 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

CVE-2017-14182
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
1.5%
2017 1 PoC

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

CVE-2015-0635
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of service (disrupted domain access), via crafted AN messages, aka Bug ID CSCup62191.

CVE-2017-17538
Software Genérico Networking
N/A
UNKNOWN
EPSS
22.3%
2017 1 PoC

MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.

CVE-2017-7340
Fortinet FortiPortal Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.

CVE-2017-9542
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2017 1 PoC

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

CVE-2014-2133
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.3%
2014 1 PoC

Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file that triggers improper LZW decompression, aka Bug ID CSCuj87565.

CVE-2015-4173
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

CVE-2017-17541
Fortinet FortiManager, FortiAnalyzer Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.

CVE-2017-3813
Cisco AnyConnect Secure Mobility Client Software for Windows Versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. Networking Windows
N/A
UNKNOWN
EPSS
1.2%
2017 CWE-264 1 PoC

A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient implementation of the access controls. An attacker could exploit this vulnerability by opening the Internet Explorer browser. An exploit could allow the attacker to use Internet Explorer with the privileges of the SYSTEM user. This may allow the attacker to execute privileged commands on the targeted system. This vulnerabilit