272 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2019-17658
Fortinet FortiClientWindows Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

CVE-2019-12550
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

CVE-2019-6699
Fortinet FortiADC Web Networking
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripting (XSS) via a field in the traffic group interface.

CVE-2019-12573
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is not sanitized, which allows a local unprivileged user to overwrite arbitrary files owned by any user on the system, including root. This creates a denial of service condition and possible data loss if leveraged by a malicious local user.

CVE-2019-5593
Fortinet FortiOS Networking
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the keys encryption password in FortiOS 6.2.0, 6.0.0 to 6.0.6, 5.6.10 and below or for user uploaded local certificates via setting an empty password in FortiOS 6.2.1, 6.2.0, 6.0.6 and below.

CVE-2019-6964
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

A heap-based buffer over-read in Service_SetParamStringValue in cosa_x_cisco_com_ddns_dml.c of the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve information disclosure and code execution by crafting an AJAX call responsible for DDNS configuration with an exactly 64-byte username, password, or domain, for which the buffer size is insufficient for the final '\0' character. This is related to the CcspCommonLibrary and WebUI modules.

CVE-2019-3972
Comodo Antivirus Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Comodo Antivirus versions 12.0.0.6810 and below are vulnerable to Denial of Service affecting CmdAgent.exe via an unprotected section object "<GUID>_CisSharedMemBuff". This section object is exposed by CmdAgent and contains a SharedMemoryDictionary object, which allows a low privileged process to modify the object data causing CmdAgent.exe to crash.

CVE-2019-3977
MikroTik RouterOS Networking
N/A
UNKNOWN
EPSS
0.9%
2019 CWE-494 1 PoC

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into "upgrading" to an older version of RouterOS and possibly reseting all the system's usernames and passwords.

CVE-2019-1566
Palo Alto Networks PAN-OS Web Networking
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.

CVE-2019-8933
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
24.4%
2019 1 PoC

In DedeCMS 5.7SP2, attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall), and then execute this file, via this sequence of steps: visiting the management page, clicking on the template, clicking on Default Template Management, clicking on New Template, and modifying the filename from ../index.html to ../index.php.

CVE-2019-11877
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID.

CVE-2019-6109
Software Genérico Networking
N/A
UNKNOWN
EPSS
9.7%
2019 3 PoCs

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVE-2019-18660
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2019 6 PoCs

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

CVE-2019-7482
SMA100 Networking
N/A
UNKNOWN
EPSS
64.6%
2019 CWE-121 2 PoCs

Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

CVE-2019-7564
Software Genérico Networking
N/A
UNKNOWN
EPSS
5.1%
2019 1 PoC

An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.

CVE-2019-13140
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.2%
2019 3 PoCs

Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.

CVE-2019-12168
Software Genérico Networking
N/A
UNKNOWN
EPSS
6.5%
2019 1 PoC

Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.

CVE-2019-15711
Fortinet FortiClientLinux Networking
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

CVE-2019-6145
Forcepoint VPN Client for Windows Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

CVE-2019-5590
FortiWeb Networking
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.