Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.35% | — | Cisco Enterprise NFV Infrastructure Software | 8/8/2019 | 24/8/2026 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Enterprise NFV Infrastructure Software | 8/8/2019 | 24/8/2026 | A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced to modify the default password when logging in to the web… | |
| Modificada | Media (6.7) | 0.72% | — | Cisco Enterprise NFV Infrastructure Software | 8/8/2019 | 24/8/2026 | A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is due to improper input validation of CLI command arguments.… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Enterprise NFV Infrastructure Software | 8/8/2019 | 24/8/2026 | A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerability is due to an incorrect implementation of authentication… | |
| Modificada | Crítica (9.8) | 2.3% | — | Cisco Enterprise NFV Infrastructure Software | 7/8/2019 | 24/8/2026 | A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient… | |
| Modificada | Alta (7.2) | 3.5% | — | Cisco Enterprise NFV Infrastructure Software | 6/7/2019 | 17/6/2026 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in NFVIS… | |
| Modificada | Alta (7.8) | 0.63% | — | Cisco Enterprise NFV Infrastructure Software | 6/7/2019 | 17/6/2026 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient input validation of a configuration file that is accessible… | |
| Modificada | Media (5.3) | 0.39% | — | Cisco Enterprise NFV Infrastructure Software | 24/1/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation in the affected software. An attacker could exploit… | |
| Modificada | Alta (8.8) | 4.4% | — | Cisco Enterprise NFV Infrastructure Software | 17/5/2018 | 17/6/2026 | A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to improper input validation of command arguments.… |