Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.3% | — | Sierra Wireless Airlink Raven XE FirmwareSierra Wireless Airlink Raven XT Firmware | 30/6/2017 | 17/6/2026 | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can be accessed without authentication, which may allow a remote attacker to perform sensitive functions including… | |
| Modificada | Alta (8.8) | 0.64% | — | Sierra Wireless Airlink Raven XE FirmwareSierra Wireless Airlink Raven XT Firmware | 30/6/2017 | 17/6/2026 | A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in user, which may allow an attacker to trick a client into making an… | |
| Modificada | Alta (8.8) | 1.7% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root. | |
| Modificada | Crítica (9.8) | 1.3% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext. | |
| Modificada | Crítica (9.8) | 1.4% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. | |
| Modificada | Crítica (9.8) | 1.6% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. | |
| Modificada | Alta (8.8) | 3.6% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. | |
| Modificada | Crítica (9.8) | 1.8% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. | |
| Modificada | Crítica (9.8) | 2.8% | — | Sierrawireless Aleos Firmware | 10/4/2017 | 17/6/2026 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. | |
| Modificada | Media (4.3) | 1.5% | — | Sierrawireless Aleos | 21/4/2016 | 17/6/2026 | ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors. | |
| Modificada | Alta (10) | 2.3% | — | Sierrawireless Aleos | 8/8/2015 | 17/6/2026 | Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session. | |
| Modificada | Media (4.3) | 1.0% | — | Sierra Wireless Aircard 760sSierra Wireless Aircard 762sSierra Wireless Aircard 763s | 23/2/2015 | 17/6/2026 | CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter. | |
| Modificada | Media (5) | 1.2% | — | III Sierra | 2/9/2014 | 17/6/2026 | Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule. | |
| Modificada | Media (4.3) | 0.93% | — | III Sierra | 2/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Alta (10) | 3.9% | — | Sierrawireless Raven X Ev-do FirmwareSierrawireless Airlink MP At&tSierrawireless Airlink MP At&t WifiSierrawireless Airlink MP Bell+15 | 15/1/2014 | 16/6/2026 | The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388. | |
| Modificada | Alta (9.3) | 1.9% | — | Sierrawireless Raven X Ev-do FirmwareSierrawireless Airlink MP At&tSierrawireless Airlink MP At&t WifiSierrawireless Airlink MP Bell+15 | 15/1/2014 | 16/6/2026 | The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action. | |
| Modificada | Media (5) | 8.9% | 💥 Exploit | Sierra Swat 4 | 24/7/2008 | 16/6/2026 | SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference; or (3) a GAMESPYRESPONSE command followed by a long RS string. | |
| Modificada | Alta (7.5) | 3.2% | — | Sierra Half-lifeValve Software Half-life | 27/6/2001 | 16/6/2026 | Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file. | |
| Modificada | Alta (7.5) | 2.3% | — | Sierra Half-lifeValve Software Half-life Dedicated Server | 27/6/2001 | 16/6/2026 | Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command. |