272 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2019-5425
EdgeMAX Networking
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.

CVE-2019-16313
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 0 PoCs

ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.

CVE-2019-3918
Alcatel Lucent I-240W-Q GPON ONT Networking
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-798 1 PoC

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.

CVE-2019-19223
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.2%
2019 1 PoC

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router by submitting a reboot.html GET request without being authenticated on the admin interface.

CVE-2019-11328
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.

CVE-2019-5587
Fortinet FortiOS Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.

CVE-2019-12986
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

CVE-2019-18910
ThinPro Linux Networking
N/A
UNKNOWN
EPSS
1.0%
2019 2 PoCs

The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

CVE-2019-17584
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of this device. An update to fix the vulnerability was published by the vendor.

CVE-2019-12147
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.5%
2019 3 PoCs

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.

CVE-2019-6695
Fortinet FortiManager Networking
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.

CVE-2019-15055
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.