Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
291 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 2.2% | — | Cisco Application Policy Infrastructure Controller (apic)Cisco Nx-os | 24/7/2015 | 17/6/2026 | Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root… | |
| Modificada | Media (4.6) | 0.44% | — | Cisco Nx-os | 3/7/2015 | 17/6/2026 | The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and… | |
| Modificada | Alta (7.2) | 0.42% | — | Cisco Nx-os | 3/7/2015 | 17/6/2026 | Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127. | |
| Modificada | Media (4.6) | 0.41% | — | Cisco Nx-os | 3/7/2015 | 17/6/2026 | Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856. | |
| Modificada | Baja (3.6) | 0.39% | — | Cisco Nx-os | 3/7/2015 | 17/6/2026 | The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416. | |
| Modificada | Media (4) | 2.0% | — | Cisco Nx-os | 27/6/2015 | 17/6/2026 | Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485. | |
| Modificada | Media (4) | 2.6% | — | Cisco Nx-os | 24/6/2015 | 17/6/2026 | Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391. | |
| Modificada | Media (6.1) | 1.0% | — | Cisco Nx-os | 20/6/2015 | 17/6/2026 | Cisco NX-OS 5.2(5) on Nexus 7000 devices allows remote attackers to cause a denial of service (device crash) by sending a malformed LLDP packet on the local network, aka Bug ID CSCud89415. | |
| Modificada | Media (5) | 3.0% | — | Cisco Nx-osCisco Nexus 1000vCisco MDS 9000 Nx-os | 12/6/2015 | 17/6/2026 | The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(0)ZN(99.67) on Nexus 3000 devices allows remote attackers… | |
| Modificada | Media (6.3) | 1.3% | — | Cisco Nx-os | 3/4/2015 | 17/6/2026 | The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq92240. | |
| Modificada | Alta (7.9) | 1.1% | — | Cisco Nx-os | 28/3/2015 | 17/6/2026 | The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589. | |
| Modificada | Media (4.9) | 0.34% | — | Cisco Nx-os | 3/2/2015 | 17/6/2026 | The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device reload) via a long CLI command, aka Bug ID CSCur54182. | |
| Modificada | Media (5) | 3.0% | — | Cisco Nx-os | 10/1/2015 | 17/6/2026 | The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129. | |
| Modificada | Media (5) | 4.7% | 💥 PoC | Cisco Nx-osCisco Nexus 5000Cisco Nexus 5010Cisco Nexus 5010p Switch+11 | 19/8/2014 | 17/6/2026 | The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616. | |
| Modificada | Media (5) | 2.1% | — | Cisco Nx-osCisco Nexus 9000 | 11/8/2014 | 17/6/2026 | Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489. | |
| Modificada | Media (4.8) | 1.1% | — | Cisco Nx-os | 14/6/2014 | 17/6/2026 | The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. | |
| Modificada | Alta (7.6) | 2.0% | — | Cisco Unified Computing System 6120xp Fabric InterconnectCisco Unified Computing System 6140xp Fabric InterconnectCisco Unified Computing System 6248up Fabric InterconnectCisco Unified Computing System 6296up Fabric Interconnect+23 | 26/5/2014 | 17/6/2026 | Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+3 | 26/5/2014 | 17/6/2026 | The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915. | |
| Modificada | Alta (7.1) | 1.9% | — | Cisco Nx-os | 26/5/2014 | 17/6/2026 | Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629. | |
| Modificada | Alta (7.1) | 1.9% | — | Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+1 | 26/5/2014 | 16/6/2026 | Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted SSH key data in an SSH session to a management interface, aka Bug ID CSCud88400. | |
| Modificada | Media (4.6) | 0.52% | — | Cisco Nx-os | 20/5/2014 | 17/6/2026 | Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217. | |
| Modificada | Media (4.6) | 0.30% | — | Cisco Nx-osCisco Nexus 7000Cisco Nexus 7000 10-slotCisco Nexus 7000 18-slot+1 | 7/5/2014 | 17/6/2026 | Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136. | |
| Modificada | Media (5) | 2.1% | — | Cisco Nx-os | 22/1/2014 | 17/6/2026 | The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bug ID CSCul88851. | |
| Modificada | Media (6.8) | 0.36% | — | Cisco Nx-os | 22/1/2014 | 17/6/2026 | Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. | |
| Modificada | Media (4.3) | 2.8% | — | Cisco Nx-os | 8/1/2014 | 17/6/2026 | The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages with IPv6, VPNv4, and VPNv6 labeled unicast-address families, which allows remote attackers to cause a denial of service (peer reset) via a crafted message, aka Bug ID CSCuj03174. |