3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2020-13417
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

CVE-2013-1145
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2013 1 PoC

Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka Bug ID CSCtl99174.

CVE-2019-3943
RouterOS Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-23 1 PoC

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).

CVE-2020-24034
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2020 3 PoCs

Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value inside of this cookie, and assume the role and permissions of the user specified. By assuming the role of the user internal, which is inaccessible to end users by default, the attacker gains the permissions of the internal account, which includes the ability to flash custom firmware

CVE-2017-3132
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.8%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

CVE-2019-6700
Fortinet FortiSIEM Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

CVE-2020-11966
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-9292
Fortinet FortiSIEMWindowsAgent Networking Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

CVE-2019-7642
Software Genérico Networking
N/A
UNKNOWN
EPSS
10.9%
2019 1 PoC

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).

CVE-2020-19323
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required

CVE-2019-7489
Email Security Appliance Networking
N/A
UNKNOWN
EPSS
21.1%
2019 CWE-285 1 PoC

A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

CVE-2020-20212
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVE-2007-1062
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
6.9%
2007 2 PoCs

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time

CVE-2007-1826
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a "specific UDP packet" to UDP port 8500, aka bug ID CSCsg60949.

CVE-2007-0057
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.2%
2007 1 PoC

Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.

CVE-2007-1669
Software Genérico Networking
N/A
UNKNOWN
EPSS
15.0%
2007 1 PoC

zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

CVE-2007-1063
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.1%
2007 2 PoCs

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.

CVE-2007-5032
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.0%
2007 1 PoC

Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters.

CVE-2014-8779
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.

CVE-2013-3085
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.