3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-20225
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

CVE-2019-15707
Fortinet FortiMail Networking
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.

CVE-2017-5633
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2017 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

CVE-2017-14182
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
1.5%
2017 1 PoC

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

CVE-2015-0635
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of service (disrupted domain access), via crafted AN messages, aka Bug ID CSCup62191.

CVE-2017-17538
Software Genérico Networking
N/A
UNKNOWN
EPSS
22.3%
2017 1 PoC

MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.

CVE-2017-7340
Fortinet FortiPortal Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.

CVE-2017-9542
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2017 1 PoC

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

CVE-2014-2133
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.3%
2014 1 PoC

Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file that triggers improper LZW decompression, aka Bug ID CSCuj87565.

CVE-2015-4173
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

CVE-2017-17541
Fortinet FortiManager, FortiAnalyzer Web Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.

CVE-2017-3813
Cisco AnyConnect Secure Mobility Client Software for Windows Versions prior to released versions 4.4.00243 and later and 4.3.05017 and later. Networking Windows
N/A
UNKNOWN
EPSS
1.2%
2017 CWE-264 1 PoC

A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to insufficient implementation of the access controls. An attacker could exploit this vulnerability by opening the Internet Explorer browser. An exploit could allow the attacker to use Internet Explorer with the privileges of the SYSTEM user. This may allow the attacker to execute privileged commands on the targeted system. This vulnerabilit

CVE-2017-6896
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.5%
2017 4 PoCs

Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.

CVE-2015-2838
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.3%
2015 4 PoCs

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in the file_name JSON member in params/xen_hotfix/0 to nitro/v1/config/xen_hotfix.

CVE-2017-5900
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.

CVE-2017-5868
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2017 2 PoCs

CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/.

CVE-2017-13717
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.0%
2017 1 PoC

Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credentials and pull any information that is stored on the device. In this case, a user's Wi-Fi credentials are stored in clear text on the device and can be pulled easily.

CVE-2017-6542
Software Genérico Networking
N/A
UNKNOWN
EPSS
22.2%
2017 2 PoCs

The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.

CVE-2014-2532
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2014 3 PoCs

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

CVE-2015-8215
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.2%
2015 1 PoC

net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum compliant value or (2) larger than the MTU of an interface, as demonstrated by a Router Advertisement (RA) message that is not validated by a daemon, a different vulnerability than CVE-2015-0272. NOTE: the scope of CVE-2015-0272 is limited to the NetworkManager product.