Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.92%—Cisco Skinny Client Control Protocol Software5/10/201817/6/2026
A vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of…
ModificadaMedia (6.8)0.40%—Cisco Skinny Client Control Protocol SoftwareCisco Unified IP PhoneCisco Unified IP Phone 7906g28/12/201216/6/2026
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
ModificadaBaja (1.5)0.27%—Cisco Unified IP Phone 7906Cisco Unified IP Phone 7911gCisco Unified IP Phone 7931gCisco Unified IP Phone 7941g+112/6/201116/6/2026
Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.
ModificadaMedia (6.6)0.26%—Cisco Unified IP Phone 7906Cisco Unified IP Phone 7911gCisco Unified IP Phone 7931gCisco Unified IP Phone 7941g+112/6/201116/6/2026
Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815.
ModificadaMedia (6.6)0.26%—Cisco Unified IP Phone 7906Cisco Unified IP Phone 7911gCisco Unified IP Phone 7931gCisco Unified IP Phone 7941g+112/6/201116/6/2026
The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecified vectors, aka Bug ID CSCtf07426.
ModificadaBaja (2.1)0.39%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.
ModificadaMedia (5)1.3%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."
ModificadaMedia (6.4)2.7%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.