Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.40%—Broadcom Brocade Sannav8/11/201917/6/2026
Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.).
ModificadaAlta (7.8)0.25%—Broadcom Brocade Sannav8/11/201917/6/2026
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.
ModificadaMedia (5.5)0.20%—Broadcom Brocade Sannav8/11/201917/6/2026
The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information.
ModificadaAlta (8.8)1.3%—Broadcom Brocade Sannav8/11/201917/6/2026
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal.
ModificadaAlta (7.5)1.7%—Brocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the…
ModificadaCrítica (9.8)3.3%—Brocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.
ModificadaAlta (8.1)7.4%💥 ExploitBrocade Network AdvisorNetapp Brocade Network Advisor22/1/201917/6/2026
A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network…
ModificadaMedia (6.5)0.54%—Broadcom Fabric Operating SystemBrocade Fabric OS8/2/201817/6/2026
A vulnerability in the IPv6 stack on Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow an attacker to cause a denial of service (CPU consumption and device hang) condition by sending crafted Router Advertisement (RA) messages to a targeted system.
ModificadaMedia (6.1)1.4%—Broadcom Fabric Operating SystemBrocade Fabric OS8/2/201817/6/2026
Cross-site scripting (XSS) vulnerability in the web-based management interface of Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) versions before 7.4.2b, 8.1.2 and 8.2.0 could allow remote attackers to execute arbitrary code or access sensitive browser-based information.
ModificadaAlta (7.5)1.1%—Brocade Netiron MLX Series FirmwareBrocade Netiron CER Series FirmwareBrocade Netiron CES Series FirmwareBrocade Netiron XMR Series Firmware8/5/201717/6/2026
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.
ModificadaAlta (7.5)15%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.
ModificadaAlta (7.5)15%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.
ModificadaCrítica (9.8)13%—Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
ModificadaCrítica (9.8)7.1%—Broadcom Brocade Network Advisor14/1/201717/6/2026
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
ModificadaAlta (8)0.47%—Brocade Virtual Traffic Manager14/1/201717/6/2026
A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in user into making administrative changes on the traffic manager cluster.
ModificadaAlta (7.5)1.8%—Brocade Netiron OS31/10/201617/6/2026
A memory corruption in the IPsec code path of Brocade NetIron OS on Brocade MLXs 5.8.00 through 5.8.00e, 5.9.00 through 5.9.00bd, 6.0.00, and 6.0.00a images could allow attackers to cause a denial of service (line card reset) via certain constructed IPsec control packets.
ModificadaAlta (7.2)0.35%—Brocade Vyatta 5400 Vrouter SoftwareBrocade Vyatta 5400 Vrouter7/10/201417/6/2026
/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.
ModificadaMedia (5)1.1%—Brocade Vyatta 5400 Vrouter SoftwareBrocade Vyatta 5400 Vrouter7/10/201417/6/2026
The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging membership in the operator group.
ModificadaAlta (9)2.7%—Brocade Vyatta 5400 Vrouter SoftwareBrocade Vyatta 5400 Vrouter7/10/201417/6/2026
The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.
ModificadaMedia (5.4)0.95%—Brocade Vyatta Vrouter SoftwareBrocade Vyatta Vrouter23/1/201417/6/2026
The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing…
ModificadaMedia (5.4)0.75%—Brocade ADXBrocade Bigiron RXBrocade FastironBrocade ICX+723/1/201417/6/2026
The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet…
ModificadaMedia (5)1.6%—Brocade Bigiron RX Switch17/7/201116/6/2026
Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.
ModificadaMedia (5)4.2%—Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+24/9/200416/6/2026
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
Orbitaley — Vulnerabilidades