3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2012-4099
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065.

CVE-2002-0545
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2002 1 PoC

Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords.

CVE-2009-4911
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2009 1 PoC

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device crash) via vectors involving SSL VPN and PPPoE transactions, aka Bug ID CSCsm77958.

CVE-2015-6420
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
19.3%
2015 7 PoCs

Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) li

CVE-2012-0941
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2012 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list.

CVE-2012-4712
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

CVE-2002-1024
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.9%
2002 1 PoC

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

CVE-2009-3710
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
3.0%
2009 1 PoC

RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.

CVE-2002-0160
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.6%
2002 1 PoC

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.

CVE-2012-0360
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2012 1 PoC

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

CVE-2012-4658
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2012 1 PoC

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.

CVE-2013-3098
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.

CVE-2012-4098
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2012 1 PoC

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13055.

CVE-2012-5687
Software Genérico Networking
N/A
UNKNOWN
EPSS
67.5%
2012 1 PoC

Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.

CVE-2012-4856
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2012 1 PoC

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2012-2500
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2012 1 PoC

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate during WebLaunch of IPsec, which allows man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz29470.

CVE-2012-2975
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later listed on a summary page.

CVE-2012-5014
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.

CVE-2012-5460
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2012 1 PoC

Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.

CVE-2012-1366
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2012 1 PoC

Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.