3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-7722
Software Genérico Networking
N/A
UNKNOWN
EPSS
49.9%
2017 1 PoC

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

CVE-2017-6957
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.7%
2017 1 PoC

Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feature is enabled in RAM, allows remote attackers to execute arbitrary code via a crafted reassociation response frame with a Cisco IE (156).

CVE-2016-6423
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2016 1 PoC

The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.

CVE-2007-1072
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2007 2 PoCs

The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors. NOTE: this issue can be leveraged remotely via CVE-2007-1063.

CVE-2016-9136
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain sensitive information by using the "crafted JavaScript" approach, related to a "Buffer Over-read" issue.

CVE-2017-17537
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.7%
2017 1 PoC

MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\0' characters, possibly related to DNS.

CVE-2017-7342
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button

CVE-2007-1834
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.

CVE-2014-3306
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.1%
2014 1 PoC

The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCup40808.

CVE-2014-4976
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.1%
2014 1 PoC

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.

CVE-2015-0558
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other routers, uses "1236790" and the MAC address to generate the WPA key.

CVE-2017-7735
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.

CVE-2017-7338
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the FortiAnalyzer Management View.

CVE-2017-14186
FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2017 0 PoCs

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via the affected parameter.

CVE-2017-0934
EdgeRouter X Networking
N/A
UNKNOWN
EPSS
0.3%
2017 CWE-269 1 PoC

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system.

CVE-2015-1188
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management functions via unknown vectors.

CVE-2004-1458
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2004 1 PoC

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

CVE-2004-1433
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2004 1 PoC

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.

CVE-2004-1760
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.1%
2004 1 PoC

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

CVE-2004-1775
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.0%
2004 1 PoC

Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.