Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Network Automation | 7/9/2021 | 17/6/2026 | Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.7% | — | Onap Open Network Automation Platform | 19/3/2020 | 17/6/2026 | In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 1.5% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Crítica (9.1) | 1.2% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected. | |
| Modificada | Crítica (9.1) | 1.2% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected. | |
| Modificada | Alta (8.8) | 1.3% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Media (6.5) | 0.58% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's password from the database. All Portal setups are affected. | |
| Modificada | Alta (7.5) | 0.73% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Crítica (9.8) | 2.1% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected. | |
| Modificada | Alta (8.8) | 1.3% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Crítica (9.8) | 1.5% | — | Onap Open Network Automation Platform | 18/3/2020 | 17/6/2026 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected. | |
| Modificada | Media (6.1) | 0.80% | — | Cisco Crosswork Change AutomationCisco Crosswork Network Automation | 26/1/2020 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Crosswork Change Automation could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of… | |
| Modificada | Alta (8.8) | 1.8% | — | Microfocus Network AutomationMicrofocus Network Operations Management | 29/4/2019 | 17/6/2026 | A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution. |