3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2021-31605
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.2%
2021 1 PoC

furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.

CVE-2007-0648
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2007 2 PoCs

Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

CVE-2014-5216
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
9.3%
2014 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action to nps/servlet/webacc, (2) the error parameter to nidp/jsp/x509err.jsp, (3) the lang parameter to sslvpn/applet_agent.jsp, or (4) the secureLoggingServersA parameter to roma/system/cntl, a different issue than CVE-2014-9412.

CVE-2015-2350
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 2 PoCs

Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.

CVE-2021-27342
Software Genérico Networking
N/A
UNKNOWN
EPSS
7.4%
2021 3 PoCs

An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack

CVE-2015-4587
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.

CVE-2023-35793
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

CVE-2021-43457
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

CVE-2021-27710
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
20.2%
2021 2 PoCs

Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes glibc's system function with untrusted input. In the function, "ip" parameter is directly passed to the attacker, allowing them to control the "ip" field to attack the OS.

CVE-2021-27201
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.

CVE-2014-9430
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action.

CVE-2015-6396
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.4%
2015 1 PoC

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

CVE-2021-20145
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.

CVE-2021-43284
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web interface).

CVE-2015-1453
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Preferences.

CVE-2021-3547
OpenVPN 3 Core Library Networking
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-305 2 PoCs

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVE-2021-35978
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.1%
2021 1 PoC

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

CVE-2007-2037
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic.

CVE-2007-1065
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.

CVE-2014-2179
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.