Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.36% | — | Nr255-vAIL2tpdAINissc IpsecAI | 15/9/2026 | 16/9/2026 | NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material. | |
| Analizada | Alta (7.6) | 4.1% | — | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Modificada | Media (5.9) | 20% | — | Checkpoint Ipsec VPN | 9/4/2019 | 17/6/2026 | Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server. | |
| Modificada | Alta (8.1) | 0.61% | — | Ncp-e NCP Secure Entry ClientSophos Ipsec Client | 9/4/2019 | 17/6/2026 | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle… | |
| Modificada | Alta (7.5) | 2.9% | — | Ipsec-tools | 6/7/2017 | 17/6/2026 | The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order… | |
| Modificada | Alta (7.8) | 9.8% | — | Ipsec-toolsCanonical Ubuntu LinuxFedoraproject FedoraF5 Big-ip Application Acceleration Manager+21 | 29/5/2015 | 17/6/2026 | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. | |
| Modificada | Alta (9.3) | 5.7% | — | Thegreenbow Ipsec VPN Client | 26/1/2010 | 16/6/2026 | Stack-based buffer overflow in vpnconf.exe in TheGreenBow IPSec VPN Client 4.51.001, 4.65.003, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a long OpenScriptAfterUp parameter in a policy (.tgb) file, related to "phase 2." | |
| Modificada | Media (5) | 2.0% | — | Ipsec-tools | 14/5/2009 | 16/6/2026 | Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the… | |
| Modificada | Media (5) | 12% | — | Ipsec-tools | 6/5/2009 | 16/6/2026 | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference. | |
| Modificada | Media (4) | 2.3% | — | Linux Ipsec Tools Racoon Daemon | 13/8/2008 | 16/6/2026 | Memory leak in racoon/proposal.c in the racoon daemon in ipsec-tools before 0.7.1 allows remote authenticated users to cause a denial of service (memory consumption) via invalid proposals. | |
| Modificada | Alta (7.8) | 3.4% | — | Ipsec-tools | 13/8/2008 | 16/6/2026 | src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows remote attackers to cause a denial of service (resource consumption). | |
| Modificada | Alta (7.2) | 0.84% | — | Safenet Ipsecdrv.sysSafenet Highassurance RemoteSafenet Softremote VPN Client | 5/2/2008 | 16/6/2026 | IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request. | |
| Modificada | Media (4.3) | 2.9% | — | Ipsec-tools | 10/4/2007 | 16/6/2026 | The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages. | |
| Modificada | Alta (7.8) | 4.4% | — | Ipsec-tools | 21/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. | |
| Modificada | Media (6.4) | 4.1% | — | Nissc Ipsec | 10/5/2005 | 16/6/2026 | Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be… | |
| Modificada | Media (5) | 2.4% | — | Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+3 | 14/3/2005 | 16/6/2026 | The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | |
| Modificada | Alta (10) | 5.4% | — | Ipsec-toolsKame RacoonRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 6/12/2004 | 16/6/2026 | The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. |