Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.35%—Swissphone Dical-red 4009AI22/8/202417/6/2026
Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.
AplazadaCrítica (9.8)0.98%—Swissphone Dical-red 4009AI22/8/202417/6/2026
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.
AplazadaAlta (8.1)0.51%—Swissphone Dical-red 4009AI22/8/202417/6/2026
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.
AplazadaAlta (8.8)0.74%—Swissphone Dical-red 4009AI22/8/202417/6/2026
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.
AplazadaMedia (6.8)0.29%—Swissphone Dical-red 4009AI22/8/202417/6/2026
An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.
AplazadaCrítica (9.4)0.88%—Swissphone Dical-red 4009AI22/8/202417/6/2026
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.
AplazadaAlta (7.6)0.61%—Swissphone Dical-red 4009AI22/8/202417/6/2026
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.