3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-7342
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button

CVE-2016-1449
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2016 1 PoC

Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy92711.

CVE-2016-9682
Software Genérico Networking
N/A
UNKNOWN
EPSS
19.5%
2016 1 PoC

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine un

CVE-2007-1834
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.

CVE-2014-3306
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.1%
2014 1 PoC

The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCup40808.

CVE-2014-4976
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.1%
2014 1 PoC

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.

CVE-2015-0558
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other routers, uses "1236790" and the MAC address to generate the WPA key.

CVE-2017-7735
Fortinet FortiOS Web Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.

CVE-2017-7338
Fortinet FortiPortal Networking
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the FortiAnalyzer Management View.

CVE-2017-14186
FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2017 0 PoCs

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via the affected parameter.

CVE-2017-0934
EdgeRouter X Networking
N/A
UNKNOWN
EPSS
0.3%
2017 CWE-269 1 PoC

Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed. An attacker with access to an operator (read-only) account could escalate privileges to admin (root) access in the system.

CVE-2015-1188
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management functions via unknown vectors.

CVE-2004-1458
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2004 1 PoC

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

CVE-2004-1433
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2004 1 PoC

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.

CVE-2004-1760
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.1%
2004 1 PoC

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

CVE-2004-1775
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.0%
2004 1 PoC

Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.

CVE-2013-6976
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2013 2 PoCs

Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication of administrators for requests that change a password via the Password and PasswordReEnter parameters, aka Bug ID CSCuh37496.

CVE-2015-0554
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
38.6%
2015 1 PoC

The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device restart) as demonstrated by a direct request to (1) wlsecurity.html or (2) resetrouter.html.

CVE-2004-1460
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2004 1 PoC

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.

CVE-2004-1434
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.0%
2004 1 PoC

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets.