3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2021-32403
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.

CVE-2014-6413
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2014 2 PoCs

A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.

CVE-2015-7272
Dell Integrated Remote Access Controller (iDRAC) Networking
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.

CVE-2021-46314
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
23.5%
2021 1 PoC

A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable domain name.

CVE-2021-43702
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

CVE-2021-3634
libssh Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-787 1 PoC

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secr

CVE-2015-6364
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960.

CVE-2021-33346
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user without authorization.

CVE-2007-2039
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP packets, (2) malformed 802.11 traffic, or (3) packets with certain header length values, aka Bug IDs CSCsg15901 and CSCsh10841.

CVE-2007-4414
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2007 1 PoC

Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the dial-up networking dialog box.

CVE-2007-0481
Software Genérico Networking
N/A
UNKNOWN
EPSS
8.2%
2007 1 PoC

Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.

CVE-2014-9382
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation

CVE-2015-6409
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.

CVE-2021-29302
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
10.1%
2021 1 PoC

TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may lead to remote code execution.

CVE-2015-2841
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.4%
2015 2 PoCs

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-stream and text/xml Content-Types.

CVE-2023-40291
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.

CVE-2014-3703
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.

CVE-2021-45885
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

CVE-2021-25102
All In One WP Security & Firewall Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect_to parameter before using it to redirect user, either via a Location header, or meta url attribute, when the Rename Login Page is active, which could lead to an Arbitrary Redirect as well as Cross-Site Scripting issue. Exploitation of this issue requires the Login Page URL value to be known, which should be hard to guess, reducing the risk

CVE-2021-33822
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.