3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2013-0126
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2013 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2) enable remote administration via the is_telnet_primary and is_telnet_secondary parameters.

CVE-2013-1142
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.

CVE-2013-7312
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.3%
2013 2 PoCs

The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVE-2013-2678
Software Genérico Networking
N/A
UNKNOWN
EPSS
71.3%
2013 2 PoCs

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

CVE-2013-3516
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.

CVE-2013-1100
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

The HTTP server in Cisco IOS on Catalyst switches does not properly handle TCP socket events, which allows remote attackers to cause a denial of service (device crash) via crafted packets on TCP port (1) 80 or (2) 443, aka Bug ID CSCuc53853.

CVE-2013-5528
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2013 2 PoCs

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

CVE-2013-3088
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

CVE-2013-7043
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device via the Restart parameter to goform/restart; (3) modify Wi-Fi settings, as demonstrated by the WpaPreSharedKey parameter to goform/wlanSecurity; or (4) modify parental controls via the ParentalPassword parameter to goform/RgParentalBasic.

CVE-2013-1124
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during an SSL session, which allows man-in-the-middle attackers to spoof ISE servers via an arbitrary certificate, aka Bug ID CSCub24309.

CVE-2013-3434
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.

CVE-2013-3433
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02276.

CVE-2013-2679
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2013 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.

CVE-2013-5039
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2013 2 PoCs

Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.

CVE-2013-2061
Software Genérico Networking Database
N/A
UNKNOWN
EPSS
1.5%
2013 1 PoC

The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.

CVE-2013-6826
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

CVE-2013-1140
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCue55093.

CVE-2013-5219
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.5%
2013 2 PoCs

Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

CVE-2013-3072
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2013 2 PoCs

An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.

CVE-2013-5092
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.5%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.