Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+525/5/201417/6/2026
Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180.
ModificadaMedia (6.3)1.3%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+529/4/201417/6/2026
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
ModificadaMedia (6.1)0.72%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+524/4/201416/6/2026
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
ModificadaMedia (6.8)1.5%—Cisco IOSCisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+423/4/201416/6/2026
Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
ModificadaMedia (6.1)0.72%—Cisco IOSCisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+623/4/201416/6/2026
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+331/10/201316/6/2026
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+331/10/201316/6/2026
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+331/10/201316/6/2026
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+331/10/201316/6/2026
Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
ModificadaAlta (7.8)2.0%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+511/4/201316/6/2026
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6)…
ModificadaAlta (7.1)2.0%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+511/4/201316/6/2026
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID…
ModificadaAlta (7.8)1.9%—Cisco ASR 1001Cisco ASR 1002Cisco ASR 1002-xCisco ASR 1002 Fixed Router+411/4/201316/6/2026
Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT and SIP ALG are enabled, allows remote attackers to cause a denial of service (card reload) by sending many SIP packets, aka Bug ID CSCuc65609.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+411/4/201316/6/2026
Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) allows remote attackers to cause a denial of service (card reload) by sending many crafted L2TP packets, aka Bug ID CSCtz23293.
ModificadaAlta (7.8)1.9%—Cisco IOS XECisco ASR 1001Cisco ASR 1002Cisco ASR 1002-x+311/4/201316/6/2026
Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 multicast packets, aka Bug ID CSCtz97563.