3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2014-2722
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.1%
2014 1 PoC

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

CVE-2013-6826
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

CVE-2019-12992
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.1%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

CVE-2014-5801
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2014 2 PoCs

The DataGard VPN + AV (aka ocshield.com) application @7F050013 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2019-3917
Alcatel Lucent I-240W-Q GPON ONT Web Networking
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-306 1 PoC

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.

CVE-2019-5424
EdgeMAX Networking
N/A
UNKNOWN
EPSS
1.9%
2019 CWE-77 1 PoC

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.

CVE-2007-3102
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.6%
2007 1 PoC

Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information.

CVE-2014-4019
Software Genérico Networking
N/A
UNKNOWN
EPSS
51.8%
2014 3 PoCs

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.

CVE-2013-1140
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCue55093.

CVE-2019-17424
Software Genérico Networking
N/A
UNKNOWN
EPSS
28.4%
2019 3 PoCs

A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.

CVE-2008-3934
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2008 2 PoCs

Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

CVE-2019-12550
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

CVE-2013-5219
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.5%
2013 2 PoCs

Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

CVE-2019-3972
Comodo Antivirus Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object data causing CmdAgent.exe to crash.

CVE-2019-8933
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
24.4%
2019 1 PoC

In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template Management, clicking on New Template, and modifying the filename from ../index.html to ../index.php.

CVE-2014-9142
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.

CVE-2013-3072
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 2 PoCs

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.

CVE-2019-15711
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

CVE-2023-37849
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.

CVE-2019-16326
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.