Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.3% | — | Cisco Unified IP Phone 6901 FirmwareCisco Unified IP Phone 6961 FirmwareCisco Unified IP Phone 6945 FirmwareCisco Unified IP Phone 6941 Firmware+33 | 18/6/2020 | 17/6/2026 | A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker… | |
| Modificada | Alta (7.1) | 2.6% | — | Cisco Unified IP Phone 7940gCisco Unified IP Phone 7960g | 16/1/2009 | 16/6/2026 | Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers. | |
| Modificada | Alta (7.8) | 6.0% | 💥 Exploit | Cisco IP Phone 7940 | 18/12/2007 | 16/6/2026 | Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability than CVE-2007-4459. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Cisco IP Phone 7940 | 11/1/2006 | 16/6/2026 | The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80. | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco IP Phone 7940 FirmwareCisco IP Phone 7960 Firmware | 11/7/2005 | 16/6/2026 | Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message. | |
| Modificada | Alta (7.5) | 6.8% | — | Cisco IOSCisco IP Phone 7940Cisco IP Phone 7960Cisco PIX Firewall Software | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by… |