Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)3.5%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on an affected device. An attacker would need to have valid administrator credentials on the…
ModificadaAlta (7.2)2.8%—Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor21/8/201917/6/2026
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient…
ModificadaAlta (7.5)2.0%—Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data21/8/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a missing…
ModificadaMedia (6.7)0.42%—Cisco Unified Computing SystemCisco Integrated Management Controller20/6/201917/6/2026
A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An attacker could exploit this…
ModificadaAlta (8)0.55%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for…
ModificadaMedia (5.3)2.2%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms. An attacker could exploit this…
ModificadaMedia (5.5)0.35%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient checking of an input buffer. An attacker could…
ModificadaMedia (5.3)1.5%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delete temporarily uploaded files. An attacker could exploit…
ModificadaMedia (5.5)0.39%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checking. An attacker could exploit this…
ModificadaMedia (6.5)1.2%—Cisco Integrated Management ControllerCisco Unified Computing System20/6/201917/6/2026
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is due to insufficient protection of data…
ModificadaCrítica (9.8)1.7%—Cisco Integrated Management Controller8/11/201817/6/2026
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this…
ModificadaMedia (6.5)1.1%—Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor5/10/201817/6/2026
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of…
ModificadaMedia (4.8)1.3%—Cisco Integrated Management Controller Supervisor7/6/201817/6/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross-site scripting (XSS) attack against a user of the…
ModificadaMedia (6.5)1.2%—IBM Integrated Management Module Firmware25/4/201817/6/2026
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.
ModificadaAlta (7.4)2.0%—IBM Integrated Management Module Firmware25/4/201817/6/2026
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.
ModificadaCrítica (9.8)1.3%—Lenovo Integrated Management Module 219/4/201817/6/2026
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than version 6.60 used in some IBM servers. An attacker providing a crafted user ID and password combination can cause a portion…
ModificadaMedia (6.5)0.84%—Lenovo Integrated Management Module FirmwareIBM Integrated Management Module Firmware20/6/201717/6/2026
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users…
ModificadaAlta (8.8)2.6%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize user-supplied HTTP input. An attacker…
ModificadaMedia (5.4)0.93%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied input by the affected software. An attacker could exploit this…
ModificadaMedia (5.4)0.97%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not…
ModificadaAlta (8.8)4.2%—Cisco Integrated Management Controller Supervisor20/4/201717/6/2026
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficiently sanitize specific values that are received as part of…
ModificadaMedia (6.8)2.2%—Cisco Integrated Management Controller Supervisor15/12/201517/6/2026
The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.
ModificadaAlta (9.4)2.8%—Cisco Integrated Management Controller SupervisorCisco Unified Computing System Director4/9/201517/6/2026
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
ModificadaMedia (5)2.6%—Cisco Integrated Management ControllerCisco Unified Computing System E140dCisco Unified Computing System E140dpCisco Unified Computing System E140s M1+410/9/201417/6/2026
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
ModificadaMedia (5)0.98%—IBM Integrated Management Module FirmwareIBM Integrated Management ModuleIBM Advanced Management Module FirmwareIBM Advanced Management Module+27/7/201417/6/2026
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands,…
Orbitaley — Vulnerabilidades