Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.4%—Cisco IOS XRCisco ASR 9001Cisco ASR 9006Cisco ASR 9010+320/9/201517/6/2026
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.
ModificadaMedia (5)1.6%—Cisco IOS XRCisco ASR 9001Cisco ASR 9006Cisco ASR 9010+311/4/201517/6/2026
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
ModificadaAlta (7.5)1.4%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+45/10/201417/6/2026
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
ModificadaMedia (4.6)1.1%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+426/8/201417/6/2026
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
ModificadaMedia (6.1)1.2%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+424/7/201417/6/2026
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.
ModificadaMedia (5.7)0.65%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+418/7/201417/6/2026
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
ModificadaMedia (6.4)2.8%—Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco ASR 9001Cisco ASR 9006+47/7/201417/6/2026
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
ModificadaAlta (7.1)2.8%—Cisco IOS XRCisco ASR 9001Cisco ASR 9006Cisco ASR 9010+314/6/201417/6/2026
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.