Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
414 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Cisco Adaptive Security Appliance Software | 22/2/2014 | 17/6/2026 | Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766. | |
| Modificada | Media (4.3) | 1.0% | — | Cisco Adaptive Security Appliance Software | 22/2/2014 | 17/6/2026 | The Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66770. | |
| Modificada | Media (4.3) | 1.5% | — | Cisco Adaptive Security Appliance | 8/1/2014 | 17/6/2026 | The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to change the user-cache contents via a replay attack involving crafted RADIUS Change of Authorization (CoA) messages, aka Bug ID CSCuj45332. | |
| Modificada | Media (4.3) | 6.9% | — | Cisco Adaptive Security Appliance | 8/1/2014 | 17/6/2026 | The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to trigger authentication-state modifications via a crafted NetBIOS logout probe response, aka Bug ID CSCuj45340. | |
| Modificada | Media (4.3) | 2.5% | — | Cisco Adaptive Security Appliance Software | 7/12/2013 | 17/6/2026 | Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (multi-protocol management outage) by making multiple management session requests, aka Bug ID CSCug33233. | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Adaptive Security Appliance SoftwareCisco Adaptive Security Appliance | 2/12/2013 | 17/6/2026 | Cisco Adaptive Security Appliance (ASA) Software does not properly handle errors during the processing of DNS responses, which allows remote attackers to cause a denial of service (device reload) via a malformed response, aka Bug ID CSCuj28861. | |
| Modificada | Media (6.4) | 0.75% | — | Cisco Adaptive Security Appliance Software | 13/11/2013 | 17/6/2026 | The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299. | |
| Modificada | Alta (7.1) | 1.2% | — | Cisco Adaptive Security Appliance Software | 13/11/2013 | 16/6/2026 | The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308. | |
| Modificada | Media (5.4) | 2.0% | — | Cisco Adaptive Security Appliance Software | 13/11/2013 | 16/6/2026 | The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCue34342. | |
| Modificada | Media (5) | 1.2% | — | Cisco Adaptive Security Appliance CX Context-aware Security Software | 4/11/2013 | 16/6/2026 | The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions via unspecified vectors, aka Bug ID CSCui94622. | |
| Modificada | Media (6.3) | 1.4% | — | Cisco Adaptive Security Appliance Software | 1/11/2013 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN portal for internal-resource browsing, aka Bug ID CSCui51199. | |
| Modificada | Media (5.4) | 1.7% | — | Cisco Adaptive Security Appliance Software | 22/10/2013 | 16/6/2026 | The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (device reload) by sending many username-from-cert IKE requests, aka Bug ID CSCua91108. | |
| Modificada | Alta (8.5) | 1.9% | — | Cisco Adaptive Security Appliance Software | 21/10/2013 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.2), 8.7 before 8.7(1.8), 9.0 before 9.0(3.6), and 9.1 before 9.1(2.8) allows remote attackers to cause a denial of service (firewall-session disruption or device reload) via crafted ICMP packets, aka Bug ID CSCui77398. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7), 8.6.x before 8.6(1.12), 9.0.x before 9.0(2.6), and 9.1.x before 9.1(1.7) allows remote attackers to cause a denial of service (device reload) via crafted HTTPS… | |
| Modificada | Alta (7.1) | 1.6% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.3), and 9.1.x before 9.1(1.8), when the DNS ALPI engine is enabled for TCP, allows remote attackers to cause a… | |
| Modificada | Alta (7.1) | 1.4% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.4), 9.0.x before 9.0(1.4), and 9.1.x before 9.1(1.2), in certain… | |
| Modificada | Alta (10) | 2.3% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.6) does… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an override-account-disable option is enabled, does not… | |
| Modificada | Alta (10) | 2.3% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCuf52468. | |
| Modificada | Alta (7.1) | 1.5% | — | Cisco Adaptive Security Appliance SoftwareCisco Firewall Services Module Software | 13/10/2013 | 16/6/2026 | The SQL*Net inspection engine in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.6), 9.0.x before 9.0(2.10), and 9.1.x before 9.1(2) and Firewall Services Module… | |
| Modificada | Alta (7.1) | 1.7% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote attackers to cause a denial of service (device reload) via a (1) ICMP or (2) ICMPv6 packet that is improperly handled during decryption, aka Bug ID CSCue18975. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Adaptive Security Appliance Software | 13/10/2013 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and forwarding outage or system hang) via packets to the… | |
| Modificada | Alta (7.1) | 1.0% | — | Cisco Adaptive Security Appliance Software | 8/9/2013 | 16/6/2026 | Cisco Adaptive Security Appliances (ASA) devices, when SMP is used, do not properly process X.509 certificates, which allows remote attackers to cause a denial of service (device crash) via a large volume of (1) SSL or (2) TLS traffic, aka Bug ID CSCuh19462. | |
| Modificada | Media (4.3) | 2.4% | — | Cisco Adaptive Security Appliance SoftwareCisco Adaptive Security Appliance | 30/8/2013 | 16/6/2026 | The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle timeout, which allows remote attackers to cause a denial of service (connection-table exhaustion) via crafted requests that use an inspected protocol, aka Bug ID CSCuh13899. | |
| Modificada | Media (4.3) | 2.1% | — | Cisco Adaptive Security Appliance SoftwareCisco Adaptive Security Appliance | 25/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WebVPN portal login page on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCug83080. |