Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.55% | — | Cisco Wireless LAN Controller Software | 18/4/2019 | 17/6/2026 | A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnerability is due to a lack of proper input- and… | |
| Modificada | Media (6.5) | 0.52% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software | 18/4/2019 | 17/6/2026 | A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP… | |
| Modificada | Media (6.5) | 0.65% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software | 18/4/2019 | 17/6/2026 | A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP… | |
| Modificada | Alta (8.8) | 0.74% | — | Cisco Wireless LAN Controller Software | 18/4/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device… | |
| Modificada | Media (6.5) | 0.65% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software | 18/4/2019 | 17/6/2026 | A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Wireless LAN Controller Software | 17/4/2019 | 17/6/2026 | A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not… | |
| Modificada | Media (4.9) | 2.0% | — | Cisco Wireless LAN Controller Software | 17/4/2019 | 17/6/2026 | A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on… | |
| Modificada | Alta (7.8) | 0.39% | — | Cisco Nx-osCisco Application Policy Infrastructure Controller Software | 6/3/2019 | 17/6/2026 | A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device. The vulnerability is due to a misconfiguration of certain sudoers files for the bashroot… | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper input validation on fields within… | |
| Modificada | Alta (7.5) | 3.3% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. The vulnerability is due to… | |
| Modificada | Media (6.5) | 4.6% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that describe filenames and pathnames. An attacker could exploit… | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco Wireless LAN Controller SoftwareCisco Wireless LAN Controller | 17/10/2018 | 17/6/2026 | A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is due to incorrect parsing of a specific TACACS attribute… | |
| Modificada | Media (5.4) | 0.58% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerability is due to the… | |
| Modificada | Media (5.3) | 2.5% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the web-based… | |
| Modificada | Media (4.8) | 1.0% | — | Cisco Wireless LAN Controller Software | 17/10/2018 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web-based interface of an affected system. The vulnerability is due to insufficient validation of user-supplied… | |
| Modificada | Alta (8.6) | 2.4% | — | Cisco Wireless LAN Controller Software | 2/5/2018 | 17/6/2026 | A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to… | |
| Modificada | Media (4.7) | 0.93% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication… | |
| Modificada | Media (5.3) | 2.3% | — | Cisco Wireless LAN Controller Software | 2/5/2018 | 17/6/2026 | A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking mechanisms in the… | |
| Modificada | Alta (7.4) | 0.50% | — | Cisco Wireless LAN Controller Software | 2/5/2018 | 17/6/2026 | A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of… | |
| Modificada | Media (6.1) | 0.57% | — | Cisco Wireless LAN Controller Software | 2/11/2017 | 17/6/2026 | A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, Layer 2 RF-adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is… | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco Wireless LAN Controller Software | 2/11/2017 | 17/6/2026 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) Discovery Request parsing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. The… | |
| Modificada | Media (6.3) | 1.6% | — | Cisco Wireless LAN Controller Software | 2/11/2017 | 17/6/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory leak that occurs on an affected… | |
| Modificada | Alta (7.4) | 0.71% | — | Cisco Wireless LAN Controller Software | 2/11/2017 | 17/6/2026 | A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due… | |
| Modificada | Alta (7.5) | 3.0% | — | Cisco Wireless LAN Controller FirmwareCisco Wireless LAN Controller Software | 6/4/2017 | 17/6/2026 | A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending… | |
| Modificada | Alta (8.8) | 1.4% | — | Cisco Wireless LAN Controller FirmwareCisco Wireless LAN Controller Software | 15/3/2017 | 17/6/2026 | A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC in a meshed topology. The vulnerability is due to insufficient authentication of the parent access point in a mesh configuration. An attacker could exploit this… |