Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without… | |
| Modificada | Media (5.9) | 1.1% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the… | |
| Modificada | Media (5.3) | 1.2% | — | OpensslNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+22 | 3/5/2022 | 17/6/2026 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that… | |
| Modificada | Alta (7.3) | 83% | 💥 PoC | Siemens Brownfield Connectivity GatewayOpensslDebian LinuxNetapp Active IQ Unified Manager+31 | 3/5/2022 | 17/6/2026 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the… | |
| Analizada | Alta (7.5) | 3.6% | 💥 PoC | Linux KernelNetapp E-series Santricity OS ControllerNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+22 | 25/12/2021 | 5/8/2026 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses. | |
| Modificada | Alta (7.8) | 0.50% | — | Linux KernelNetapp Solidfire Baseboard Management Controller FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+18 | 7/6/2021 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. | |
| Modificada | Media (6.7) | 0.93% | 💥 PoC | Linux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+15 | 23/11/2020 | 17/6/2026 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. | |
| Modificada | Alta (7.5) | 2.1% | — | NTPRedhat Enterprise LinuxNetapp Data OntapNetapp HCI Management Node+13 | 17/4/2020 | 17/6/2026 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. | |
| Modificada | Alta (7.8) | 0.58% | — | Netapp Fabric-attached Storage 8700 FirmwareNetapp Fabric-attached Storage 8300 FirmwareNetapp ALL Flash Fabric-attached Storage A400 Firmware | 26/2/2020 | 17/6/2026 | NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access. |