Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Wireless LAN Controller SoftwareCisco Business Access PointsCisco Access Points+1 | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of… | |
| Modificada | Alta (8.6) | 1.4% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication… | |
| Modificada | Alta (7.4) | 0.49% | — | Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software | 24/9/2020 | 17/6/2026 | A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by… | |
| Modificada | Media (6.5) | 0.31% | — | Qualcomm Apq8053 FirmwareQualcomm Ipq4019 FirmwareQualcomm Ipq8064 FirmwareQualcomm Msm8909w Firmware+9 | 8/9/2020 | 17/6/2026 | u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer… | |
| Modificada | Media (6.5) | 0.50% | — | Cisco Aironet 1542i FirmwareCisco Aironet 1542d FirmwareCisco Aironet 1562i FirmwareCisco Aironet 1562e Firmware+13 | 15/4/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an… | |
| Modificada | Alta (7.4) | 0.80% | — | Cisco Aironet 3700e FirmwareCisco Aironet 3700i FirmwareCisco Aironet 3700p FirmwareCisco Access Points | 17/7/2019 | 17/6/2026 | A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling condition for client… | |
| Modificada | Media (4.4) | 0.77% | — | Cisco Aironet Access Point Firmware | 18/4/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An attacker could exploit this vulnerability by accessing the… | |
| Modificada | Media (6.5) | 0.63% | — | Cisco Aironet Access Point Firmware | 18/4/2019 | 17/6/2026 | A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has port security configured. The vulnerability exists because… | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Aironet Access Point Firmware | 18/4/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. The attacker would need valid administrator device credentials. The vulnerability is due to improper… | |
| Modificada | Media (5.7) | 0.56% | — | Cisco Aironet Access Point Firmware | 18/4/2019 | 17/6/2026 | A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation on QoS fields within Wi-Fi frames by the affected… | |
| Modificada | Alta (7.5) | 0.64% | — | Arubanetworks ArubaosArubanetworks 203rp FirmwareArubanetworks 203r FirmwareArubanetworks Ap-300 Series Access Points Firmware+1 | 7/12/2018 | 17/6/2026 | A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable… | |
| Modificada | Alta (7.4) | 0.86% | — | Cisco Access Points | 17/10/2018 | 17/6/2026 | A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a corruption of certain timer mechanisms triggered by specific roaming… | |
| Modificada | Media (6.8) | 0.52% | — | Cisco Aironet Access Points | 17/10/2018 | 17/6/2026 | A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a deadlock condition that may occur when an affected AP attempts to… | |
| Modificada | Media (4.1) | 0.46% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The vulnerability is due to the AP… | |
| Modificada | Media (4.3) | 0.58% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. A successful exploit could prevent… | |
| Modificada | Media (4.7) | 0.93% | — | Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation of authentication… | |
| Modificada | Alta (8.6) | 3.8% | — | Cisco Aironet Access Point Software | 2/5/2018 | 17/6/2026 | A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access Points could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to… | |
| Modificada | Alta (8.8) | 2.3% | — | Ruckuswireless Solo Access Point FirmwareRuckuswireless Smartzone Managed Access Point Firmware | 14/2/2018 | 17/6/2026 | Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems. | |
| Modificada | Alta (7.5) | 0.74% | — | Cisco Aironet Access Point Firmware | 16/5/2017 | 17/6/2026 | A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges. The vulnerability is due to… | |
| Modificada | Media (6.7) | 0.42% | — | Cisco Aironet Access Point | 7/4/2017 | 17/6/2026 | A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, local attacker to gain unrestricted root access to the underlying Linux operating system. The root Linux shell is provided for advanced troubleshooting and should not be… | |
| Modificada | Crítica (9.8) | 4.5% | — | Cisco Aironet Access Point Firmware | 6/4/2017 | 17/6/2026 | A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerability is due to the existence of default credentials for an affected device that… | |
| Modificada | Crítica (9.8) | 5.3% | — | Cisco Aironet Access Point Software | 15/3/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper implementation of authentication for accessing certain web… | |
| Modificada | Media (4.3) | 0.54% | — | Cisco Aironet Access Point Software | 26/1/2017 | 17/6/2026 | A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail. Affected Products: This vulnerability affects Cisco Mobility Express 2800 Series and… | |
| Modificada | Media (4.3) | 0.45% | — | Cisco Aironet Access Point Software | 26/1/2017 | 17/6/2026 | A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid connections and be unable to process new incoming requests. More Information:… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Aironet Access Point Software | 22/8/2016 | 17/6/2026 | The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (device reload) via crafted 802.11 frames, aka Bug ID CSCva06192. |