321 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-20212
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVE-2020-5147
SonicWall NetExtender Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-428 1 PoC

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.

CVE-2020-20264
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Mikrotik RouterOs before 6.47 (stable tree) in the /ram/pckg/advanced-tools/nova/bin/netwatch process. An authenticated remote attacker can cause a Denial of Service due to a divide by zero error.

CVE-2020-9436
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
1.2%
2020 4 PoCs

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.

CVE-2020-7931
Software Genérico Networking
N/A
UNKNOWN
EPSS
32.4%
2020 1 PoC

In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the DefaultObjectWrapper class makes certain Java functions accessible to a template.

CVE-2020-20237
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-20265
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An authenticated remote attacker can cause a Denial of Service due via a crafted packet.

CVE-2020-12246
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.6%
2020 5 PoCs

Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.

CVE-2020-20236
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-15314
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.

CVE-2020-6643
Fortinet FortiIsolator Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS).

CVE-2020-5759
Grandstream UCM6200 Series Networking
N/A
UNKNOWN
EPSS
10.2%
2020 CWE-78 1 PoC

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.

CVE-2020-8953
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

CVE-2020-29669
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.6%
2020 3 PoCs

In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.

CVE-2020-7244
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.8%
2020 1 PoC

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router IP Address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

CVE-2020-36109
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
12.9%
2020 2 PoCs

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

CVE-2020-22181
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi

CVE-2020-25289
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).

CVE-2020-25988
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.2%
2020 4 PoCs

UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.

CVE-2020-20225
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.