Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)1.1%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+426/8/201417/6/2026
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
ModificadaMedia (6.1)1.2%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+424/7/201417/6/2026
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.
ModificadaMedia (5.7)0.65%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+418/7/201417/6/2026
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
ModificadaMedia (6.4)2.8%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+47/7/201417/6/2026
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
ModificadaAlta (7.1)2.8%—Cisco IOS XRCisco ASR 9001Cisco ASR 9006Cisco ASR 9010+314/6/201417/6/2026
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.
ModificadaMedia (5)2.0%—Cisco IOS XR20/5/201417/6/2026
The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149.
ModificadaMedia (5)2.0%—Cisco IOS XR20/5/201417/6/2026
The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.
ModificadaMedia (6.1)0.74%—Cisco IOS XR5/4/201417/6/2026
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
ModificadaMedia (5)1.2%—Cisco IOS XR29/11/201317/6/2026
The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug ID CSCuh43144.
ModificadaMedia (4.3)1.1%—Cisco IOS XR8/11/201316/6/2026
The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.
ModificadaAlta (7.1)1.7%—Cisco IOS XR25/10/201316/6/2026
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
ModificadaAlta (7.8)1.3%—Cisco IOS XR2/10/201316/6/2026
The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.
ModificadaMedia (5)2.3%—Cisco IOS XR27/9/201316/6/2026
The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963.
ModificadaMedia (5)3.0%—Cisco IOS XR30/8/201316/6/2026
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.
ModificadaMedia (4.6)0.31%—Cisco IOS XR13/8/201316/6/2026
Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.
ModificadaMedia (5)1.2%—Cisco IOS XR23/5/201316/6/2026
Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.
ModificadaMedia (4)0.98%—Cisco IOS XR3/5/201316/6/2026
The SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (process restart) via crafted SNMP packets, aka Bug ID CSCue69472.
ModificadaMedia (4)0.98%—Cisco IOS XR29/4/201316/6/2026
Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.
ModificadaMedia (5)1.2%—Cisco IOS XR26/3/201316/6/2026
The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted TE packets, aka Bug ID CSCue04000.
ModificadaAlta (7.1)2.3%—Cisco IOSCisco IOS XECisco IOS XR27/9/201216/6/2026
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
ModificadaAlta (7.8)2.2%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco CRS Performance Route Processor31/5/201216/6/2026
Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593.
ModificadaAlta (7.8)1.8%—Cisco IOS XR2/5/201216/6/2026
The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.
ModificadaAlta (7.8)1.7%—Cisco IOS XRCisco ASR 9006 RouterCisco ASR 9010 Router28/7/201116/6/2026
Unspecified vulnerability in Cisco IOS XR 4.1.x before 4.1.1 on Cisco Aggregation Services Routers (ASR) 9000 series devices allows remote attackers to cause a denial of service (line-card reload) via an IPv4 packet, aka Bug ID CSCtr26695.
ModificadaAlta (7.8)1.2%—Cisco IOS XR31/5/201116/6/2026
Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCto45095.
ModificadaAlta (7.8)1.2%—Cisco IOS XR31/5/201116/6/2026
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.