Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

1016 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.2%—Cisco SN 5420 Storage Router Firmware9/1/200216/6/2026
Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization.
ModificadaMedia (5)2.0%—Cisco SN 5420 Storage Router Firmware9/1/200216/6/2026
Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers.
ModificadaMedia (5)3.3%—Cisco SN 5420 Storage Router Firmware9/1/200216/6/2026
Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface.
ModificadaAlta (7.5)1.8%—Speedxess Ha-120 DSL Router31/12/200116/6/2026
SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain access.
ModificadaAlta (7.5)1.7%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.
ModificadaMedia (5)1.7%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments.
ModificadaAlta (7.5)1.4%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.
ModificadaAlta (7.5)1.4%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.
ModificadaAlta (7.5)1.7%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.
ModificadaAlta (7.5)1.6%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.
ModificadaMedia (5)1.7%—Cisco 12000 Router6/12/200116/6/2026
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.
ModificadaMedia (5)2.2%—Cayman 3220-h DSL Router18/10/200116/6/2026
El router DSL Cayman 3220-H 1.0 permite a atacantes remotos producir una denegación de servicio (ostia) mediante una serie de paquetes SYN (peticiones de conexión de TCP/IP.
ModificadaMedia (5)1.9%—Cisco SN 5420 Storage Router Firmware11/7/200116/6/2026
Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.
ModificadaAlta (7.5)3.6%—Cayman 3220-h DSL Router11/6/200116/6/2026
Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.
ModificadaMedia (5)1.4%—Netopia R9100 Router26/3/200116/6/2026
Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.
ModificadaMedia (5)1.3%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.
ModificadaMedia (5)1.7%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.
ModificadaMedia (5)1.3%—Cisco Broadband Operating SystemCisco 6XX Routers16/2/200116/6/2026
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.
ModificadaMedia (5)2.5%—Netopia 650-st Isdn Router9/1/200116/6/2026
Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.
ModificadaMedia (4.6)0.49%—Cisco SN 5420 Storage Router Firmware8/1/200116/6/2026
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged.
ModificadaMedia (5)1.7%—Cisco IOSCisco Gigabit Switch Router 12008Cisco Gigabit Switch Router 12012Cisco Gigabit Switch Router 1201620/10/200016/6/2026
Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.
ModificadaMedia (5)2.5%💥 ExploitCayman 3220-h DSL RouterCayman Gatorsurf23/5/200016/6/2026
The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.
ModificadaMedia (5)3.2%💥 ExploitCayman 3220-h DSL RouterCayman Gatorsurf17/5/200016/6/2026
The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.
ModificadaBaja (3.6)1.8%💥 ExploitNetopia R-series Routers16/5/200016/6/2026
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
ModificadaBaja (2.1)0.51%—Cisco IOSCisco Router 2500Cisco Router 2600Cisco Router 3600+33/5/200016/6/2026
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.