Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
414 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 19/4/2018 | 11/8/2026 | A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The… | |
| Modificada | Media (5.9) | 15% | — | Cavium Nitrox SSL SDKCavium Nitrox V SSL SDKCavium Octeon SDKCavium Octeon SSL SDK+10 | 5/3/2018 | 17/6/2026 | Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Crítica (10) | 87% | 💥 Exploit | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 29/1/2018 | 11/8/2026 | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when… | |
| Modificada | Media (5.9) | 13% | — | Cisco Adaptive Security Appliance 5505 FirmwareCisco Adaptive Security Appliance 5510 FirmwareCisco Adaptive Security Appliance 5520 FirmwareCisco Adaptive Security Appliance 5540 Firmware+1 | 15/12/2017 | 17/6/2026 | A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Adaptive Security Appliance | 5/10/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka HREF XSS. The vulnerability is due to… | |
| Modificada | Alta (8.6) | 6.5% | — | Cisco Adaptive Security Appliance Software | 5/10/2017 | 17/6/2026 | A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete… | |
| Modificada | Media (4.2) | 1.7% | — | Cisco Nx-osCisco Nx-os FOR Nexus 5500 Platform SwitchesCisco Nx-os FOR Nexus 5600 Platform SwitchesCisco Nx-os FOR Nexus 7700 Series Switches+3 | 7/8/2017 | 17/6/2026 | Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an… | |
| Modificada | Media (6.1) | 1.7% | — | Cisco Adaptive Security Appliance Software | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1(6.11) and 9.4(1.2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka WebVPN XSS. The… | |
| Modificada | Media (5.4) | 1.2% | — | Cisco Adaptive Security Appliance Software | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient… | |
| Modificada | Alta (7.5) | 3.2% | — | Cisco Adaptive Security Appliance Software | 7/8/2017 | 17/6/2026 | A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between… | |
| Modificada | Alta (8.1) | 0.65% | — | Cisco Adaptive Security Appliance Software | 27/6/2017 | 16/6/2026 | ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim, ASA 5510 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 8.4.x before 8.4.7 Interim, 8.2.x before 8.2.5 Interim, 9.1.x before 9.1.6 Interim, ASA 5555-X… | |
| Modificada | Alta (7.7) | 3.0% | — | Cisco Adaptive Security Appliance Software | 20/4/2017 | 17/6/2026 | A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of an affected system. The vulnerability is due to insufficient validation of the IKEv1 XAUTH parameters passed during an IKEv1 negotiation. An attacker could… | |
| Modificada | Alta (7.7) | 2.8% | — | Cisco Adaptive Security Appliance Software | 20/4/2017 | 17/6/2026 | A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of malformed IPsec packets. An attacker could exploit this vulnerability by sending malformed IPsec packets to the affected… | |
| Modificada | Alta (8.6) | 4.6% | — | Cisco Adaptive Security Appliance Software | 20/4/2017 | 17/6/2026 | A vulnerability in the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of crafted SSL or TLS packets. An attacker could exploit this… | |
| Modificada | Alta (8.7) | 2.4% | — | Cisco Adaptive Security Appliance Software | 20/4/2017 | 17/6/2026 | A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt the information present in the device's local DNS cache. The vulnerability is due to a flaw in handling crafted DNS response messages. An attacker could exploit this… | |
| Modificada | Media (4) | 1.7% | — | Cisco Adaptive Security Appliance Software | 20/4/2017 | 17/6/2026 | A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause Cisco ASA and FTD to drop any further incoming traffic on all interfaces, resulting… | |
| Modificada | Media (5.3) | 2.1% | — | Cisco Adaptive Security Appliance Software | 17/3/2017 | 17/6/2026 | A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass the access control list (ACL) for specific TCP and UDP traffic. More Information: CSCvc68229. Known… | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | Cisco Adaptive Security Appliance Software | 9/2/2017 | 17/6/2026 | A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Firepower Services FOR Adaptive Security Appliance | 14/12/2016 | 17/6/2026 | A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services, Advanced… | |
| Modificada | Media (5.9) | 1.8% | — | Cisco Adaptive Security Appliance Software | 19/11/2016 | 17/6/2026 | A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to inject arbitrary XML commands on the affected system. More Information: CSCva38556. Known Affected Releases: 9.1(6.10). Known Fixed Releases: 100.11(0.75)… | |
| Modificada | Alta (8.1) | 6.7% | — | Cisco Adaptive Security Appliance Software | 27/10/2016 | 17/6/2026 | A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the affected code area. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Adaptive Security Appliance Software | 27/10/2016 | 17/6/2026 | A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper handling of crafted packets during the enrollment operation. An attacker could exploit… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Adaptive Security Appliance Software | 6/10/2016 | 17/6/2026 | The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942. | |
| Analizada | Alta (7.8) | 23% | ⚠ Explotación activa💥 Exploit | Cisco Adaptive Security Appliance Software | 18/8/2016 | 17/6/2026 | Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA. | |
| Analizada | Alta (8.8) | 88% | ⚠ Explotación activa💥 Exploit | Cisco PIX Firewall SoftwareCisco Adaptive Security Appliance SoftwareCisco ASA 1000v Cloud Firewall Software | 18/8/2016 | 17/6/2026 | Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151… |