3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2017-14115
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.0%
2017 1 PoC

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures ssh-permanent-enable WAN SSH logins to the remotessh account with the 5SaP9I26 password, which allows remote attackers to access a "Terminal shell v1.0" service, and subsequently obtain unrestricted root privileges, by establishing an SSH session and then entering certain shell metacharacters and BusyBox commands.

CVE-1999-0998
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
1999 1 PoC

Cisco Cache Engine allows an attacker to replace content in the cache.

CVE-1999-1464
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
1999 1 PoC

Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.

CVE-2017-6640
Cisco Prime Data Center Network Manager Server Static Credential Vulnerability Networking
N/A
UNKNOWN
EPSS
53.1%
2017 CWE-264 1 PoC

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to

CVE-2015-1451
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.

CVE-1999-0415
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
1999 1 PoC

The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.

CVE-2017-5329
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.

CVE-1999-0221
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
1999 1 PoC

Denial of service of Ascend routers through port 150 (remote administration).

CVE-2020-21933
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.

CVE-2019-13115
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
42.4%
2019 1 PoC

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.

CVE-2020-13417
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

CVE-2013-1145
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2013 1 PoC

Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka Bug ID CSCtl99174.

CVE-2019-3943
RouterOS Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-23 1 PoC

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).

CVE-2020-24034
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2020 3 PoCs

Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value inside of this cookie, and assume the role and permissions of the user specified. By assuming the role of the user internal, which is inaccessible to end users by default, the attacker gains the permissions of the internal account, which includes the ability to flash custom firmware

CVE-2019-6700
Fortinet FortiSIEM Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

CVE-2020-11966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-9292
Fortinet FortiSIEMWindowsAgent Networking Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVE-2019-7642
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.9%
2019 1 PoC

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).

CVE-2020-19323
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

CVE-2019-7489
Email Security Appliance Networking
N/A
UNKNOWN
EPSS
21.1%
2019 CWE-285 1 PoC

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.