Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)84%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+69/8/201917/6/2026
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
ModificadaCrítica (9.8)27%—Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+89/8/201917/6/2026
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
ModificadaAlta (7.1)8.3%—Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+35/8/201917/6/2026
Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.
ModificadaMedia (5.9)0.96%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to…
ModificadaCrítica (9.8)2.8%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an…
ModificadaMedia (6.5)1.3%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker…
ModificadaAlta (8.8)1.7%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface has been identified, which may allow an attacker to hijack web sessions.
ModificadaMedia (6.5)0.44%—Belden Hirschmann Rs20-0900mmm2tdauBelden Hirschmann Rs20-0900nnm4tdauBelden Hirschmann Rs20-0900vvm2tdauBelden Hirschmann Rs20-1600l2l2sdau+1306/3/201817/6/2026
An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through…
ModificadaMedia (5.3)0.95%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.
ModificadaAlta (7.1)0.44%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.
ModificadaMedia (6.5)0.92%—Belden Hirschmann Gecko Lite Managed Switch Firmware30/6/201717/6/2026
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently verify that the request is being sent to the expected destination.
ModificadaMedia (5.9)1.9%—Belden Hirschmann Gecko Lite Managed Switch Firmware13/2/201717/6/2026
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a location that is accessible without authentication by path traversal.
ModificadaMedia (5.3)0.80%—Belden Hirschmann FirmwareBelden Hirschmann L2B18/2/201617/6/2026
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.
Orbitaley — Vulnerabilidades