« Volver al listado

Infoblox

Infoblox Nios: vulnerabilidades y CVE

Infoblox Nios tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses2
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-61880Alta (8.8)0.61%—12 feb 2026
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-61879Alta (7.7)0.28%—12 feb 2026
In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.
CVE-2024-37567Crítica (9.1)0.35%—27 feb 2025
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
CVE-2024-37566Crítica (9.8)0.46%—27 feb 2025
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2024-36047Crítica (9.8)0.44%—27 feb 2025
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
CVE-2024-36046Crítica (9.8)0.41%—27 feb 2025
Infoblox NIOS through 8.6.4 executes with more privileges than required.
CVE-2022-28975Media (5.4)0.35%—9 ene 2024
A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.
CVE-2023-37249Alta (8.8)0.73%—25 ago 2023
Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.
CVE-2020-15303Media (6.5)0.86%—28 jun 2021
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
CVE-2018-10239Media (6.7)0.38%—17 jun 2019
A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to temporarily gain additional privileges on an affected device…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1059 Command and Scripting Interpreter2
  3. T1210 Exploitation of Remote Services2
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1
  6. T1078.002 Domain Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Infoblox