3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2019-12576
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the P

CVE-2019-3981
WinBox Networking
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-300 1 PoC

MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

CVE-2008-2056
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.9%
2008 1 PoC

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.1.x before 8.1(1)1 allows remote attackers to cause a denial of service (device reload) via a crafted Transport Layer Security (TLS) packet to the device interface.

CVE-2013-7417
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery (CSRF) protection mechanism by setting the Referer.

CVE-2019-9657
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.

CVE-2020-21936
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.

CVE-2020-10809
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

CVE-2008-0029
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2008 1 PoC

Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.

CVE-2019-5426
EdgeMAX Networking
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-287 1 PoC

In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploit this bug to access local services or forward traffic through the device if SSH is enabled in the system settings.

CVE-2020-11968
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-25858
Qualcomm QCMAP Networking
N/A
UNKNOWN
EPSS
2.7%
2020 CWE-476 1 PoC

The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This version of QCMAP is used in many kinds of networking devices, primarily mobile hotspots and LTE routers.

CVE-2014-4871
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter.

CVE-2020-20249
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenticated remote attacker can cause a Denial of Service.

CVE-2020-17352
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.

CVE-2020-25200
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2020 1 PoC

Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design

CVE-2019-20213
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2019 4 PoCs

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.

CVE-2020-20236
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-13885
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-6640
Fortinet FortiAnalyzer Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.

CVE-2013-1414
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings or (2) policies, or (3) restart the device via a rebootme action to system/maintenance/shutdown.