Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.15% | — | Cisco IOS XEAICisco MerakiAI | 25/3/2026 | 17/6/2026 | A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path… | |
| Aplazada | Alta (7.5) | 0.43% | — | Meraki Mr9600AIMeraki Mx4200AI | 25/2/2026 | 17/6/2026 | Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200. | |
| Aplazada | Media (6.2) | 0.20% | — | Meraki Mr9600AIMeraki Mx4200AI | 25/2/2026 | 17/6/2026 | Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a new mesh device to the network to gain access to sensitive information, including the password for admin access to the web interface and the Wi-Fi passwords.This issue affects MR9600: 1.0.4.205530;… | |
| Aplazada | Alta (8.6) | 0.54% | — | Cisco Anyconnect VPN ServerAICisco Meraki MXAICisco Meraki Z Series Teleworker GatewayAI | 18/6/2025 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to variable… | |
| Aplazada | Alta (7.7) | 0.69% | — | Cisco AnyconnectAICisco Meraki MXAICisco Meraki Z SeriesAI | 2/4/2025 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user… | |
| Aplazada | Media (5.3) | 0.36% | — | Cisco Meraki Mx67AICisco Meraki Mx68AI | 4/3/2025 | 17/6/2026 | A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the… | |
| Modificada | Media (5.3) | 0.45% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for… | |
| Modificada | Media (5.9) | 0.39% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN service on an affected… | |
| Modificada | Alta (7.5) | 0.52% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions.… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Alta (7.5) | 0.55% | — | Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+21 | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. This vulnerability is due to insufficient resource management when… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Z4C FirmwareCisco Meraki Z4 FirmwareCisco Meraki Z3C FirmwareCisco Meraki Z3 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Modificada | Alta (7.5) | 0.51% | — | Cisco Meraki Mx65 FirmwareCisco Meraki Mx64 FirmwareCisco Meraki Z4C FirmwareCisco Meraki Z4 Firmware+21 | 2/10/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of… | |
| Analizada | Alta (7.3) | 0.20% | — | Cisco Meraki Systems Manager | 12/9/2024 | 17/6/2026 | — | |
| Modificada | Media (5.8) | 0.52% | — | Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Unified Threat DefenseCisco Meraki MX Security Appliance Firmware | 1/11/2023 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a flaw in the FTP module of the Snort detection engine. An attacker could exploit this… | |
| Modificada | Media (5.8) | 0.95% | — | Cisco Secure Firewall Threat DefenseCisco Cyber VisionCisco Meraki MX Security Appliance Firmware | 15/11/2022 | 11/8/2026 | Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Meraki Mx64 FirmwareCisco Meraki Mx64w FirmwareCisco Meraki Mx65 FirmwareCisco Meraki Mx65w Firmware+19 | 26/10/2022 | 17/6/2026 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters… | |
| Modificada | Media (4.7) | 0.81% | — | Ieee 802.2Ietf P802.1qCisco Catalyst 6503-e FirmwareCisco Catalyst 6504-e Firmware+92 | 27/9/2022 | 17/6/2026 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers. | |
| Modificada | Media (6.5) | 3.1% | — | Alfa Awus036h FirmwareCisco Meraki Gr10 FirmwareCisco Meraki Gr60 FirmwareCisco Meraki Mr20 Firmware+91 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP… | |
| Modificada | Media (6.5) | 2.9% | — | Alfa Awus036h FirmwareSiemens Scalance W1748-1 FirmwareSiemens Scalance W1750d FirmwareSiemens Scalance W1788-1 Firmware+190 | 11/5/2021 | 17/6/2026 | An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. | |
| Modificada | Media (5.3) | 6.5% | — | NetbsdDebian LinuxArista C-100 FirmwareArista C-110 Firmware+162 | 11/5/2021 | 17/6/2026 | An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to… | |
| Modificada | Baja (3.5) | 3.6% | — | Ieee 802.11Linux Mac80211Microsoft Windows 10Microsoft Windows 7+177 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary… | |
| Modificada | Baja (2.6) | 2.6% | — | Ieee 802.11Linux Mac80211Debian LinuxArista C-100 Firmware+164 | 11/5/2021 | 17/6/2026 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or… | |
| Modificada | Media (5.3) | 2.0% | — | Cisco Secure Firewall Management CenterCisco Secure Firewall Threat DefenseCisco IOS XESnort+12 | 13/1/2021 | 11/8/2026 | Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is… | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Meraki MR 24 FirmwareCisco Meraki MR 25 FirmwareCisco Meraki MS 10 FirmwareCisco Meraki MS 9 Firmware+3 | 8/11/2018 | 17/6/2026 | A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish… |