Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)6.1%—Cisco IOSCisco Css11000 Content Services SwitchCisco PIX FirewallOpenssl+11/12/200316/6/2026
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
ModificadaMedia (6.4)1.2%—Cisco PIX Firewall Software31/12/200216/6/2026
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
ModificadaMedia (5)2.0%—Cisco PIX Firewall Software31/12/200216/6/2026
Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.
ModificadaAlta (7.5)0.70%—Cisco PIX Firewall4/10/200216/6/2026
The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques.
ModificadaAlta (7.1)3.3%—Cisco IOSCisco PIX Firewall SoftwareCisco Css11000 Content Services SwitchCisco Catos4/10/200216/6/2026
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
ModificadaBaja (2.1)0.46%—Cisco PIX Firewall Manager10/10/200116/6/2026
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.
ModificadaMedia (5)10%💥 ExploitCisco PIX Firewall 515Cisco PIX Firewall 52018/6/200116/6/2026
Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.
ModificadaAlta (7.5)7.1%💥 ExploitCisco PIX Firewall Software11/12/200016/6/2026
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.
ModificadaMedia (5)3.5%💥 ExploitCisco PIX Firewall Software11/12/200023/9/2026
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.
ModificadaMedia (5)9.2%💥 ExploitCisco PIX Firewall20/3/200016/6/2026
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.
ModificadaAlta (7.5)2.2%—Checkpoint Firewall-1Cisco PIX Firewall Software12/2/200016/6/2026
Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
ModificadaMedia (5)1.5%—Cisco PIX Firewall Software31/8/199816/6/2026
Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
ModificadaMedia (5)1.1%—Cisco IOSCisco PIX Firewall Software18/8/199816/6/2026
Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
ModificadaAlta (7.5)1.9%—Cisco PIX Firewall15/7/199816/6/2026
By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.
Orbitaley — Vulnerabilidades