Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

31 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.46%—Cisco IP Dect 110 FirmwareCisco IP Dect 210 FirmwareCisco Unified IP Phone 6901 FirmwareCisco Unified SIP Phone 3905 Firmware21/11/202317/6/2026
A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation of user-supplied…
ModificadaAlta (7.5)10%—Cisco IP Phone 6871 FirmwareCisco IP Phone 6861 FirmwareCisco IP Phone 6851 FirmwareCisco IP Phone 6841 Firmware+173/3/202317/6/2026
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (6.5)0.61%—Cisco IP Phone 7800 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 FirmwareCisco IP Phone 7832 Firmware+1820/1/202317/6/2026
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability…
ModificadaAlta (7.4)1.2%—Cisco Unified IP Phone 6911 FirmwareCisco Unified IP Phone 6921 FirmwareCisco Unified IP Phone 6941 FirmwareCisco Unified IP Phone 6945 Firmware+715/6/202217/6/2026
A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing process that could result in duplicated…
ModificadaMedia (4.6)0.35%—Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 Firmware+1614/1/202217/6/2026
A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. An attacker could…
ModificadaMedia (5.3)1.3%—Cisco Unified IP Phone 6901 FirmwareCisco Unified IP Phone 6961 FirmwareCisco Unified IP Phone 6945 FirmwareCisco Unified IP Phone 6941 Firmware+3318/6/202017/6/2026
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to improper access controls on the web-based management interface of an affected device. An attacker…
ModificadaAlta (7.5)3.4%—Cisco Unified IP Phone FirmwareCisco IP Phone Firmware7/6/201817/6/2026
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit…
ModificadaAlta (7.5)8.3%—Cisco IOS XECisco Webex Meeting CenterCisco DX Series IP Phones FirmwareCisco IP Phone 7800 Series Firmware+1021/4/201617/6/2026
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
ModificadaAlta (7.1)2.8%—Cisco Unified IP Phones 9900 Series Firmware30/6/201517/6/2026
The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976.
ModificadaMedia (5)1.4%—Cisco Unified IP Phones 9900 Series Firmware7/2/201517/6/2026
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.
ModificadaMedia (5)2.2%—Cisco Unified IP Phones 9900 Series Firmware7/2/201517/6/2026
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139.
ModificadaMedia (5)1.4%—Cisco Unified IP Phones 9971 FirmwareCisco Unified IP Phones 9951 Firmware7/2/201517/6/2026
The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.
ModificadaMedia (4.6)0.30%—Cisco Unified IP Phones 9900 Series Firmware7/2/201517/6/2026
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474.
ModificadaMedia (4.6)0.30%—Cisco Unified IP Phones 9971 FirmwareCisco Unified IP Phones 9951 Firmware7/2/201517/6/2026
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.
ModificadaMedia (4.3)0.71%—Cisco Unified IP Phone 7960g22/2/201417/6/2026
The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795.
ModificadaMedia (5.4)2.7%—Cisco Unified IP Phones 9900 Series FirmwareCisco Unified IP Phone 9951Cisco Unified IP Phone 997110/1/201417/6/2026
Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.
ModificadaMedia (6.6)0.28%—Cisco Unified IP Phone FirmwareCisco Unified IP Phone 8961Cisco Unified IP Phone 9951Cisco Unified IP Phone 997113/11/201317/6/2026
The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
ModificadaMedia (6)0.27%—Cisco Unified IP Phones 9900 Series FirmwareCisco Unified IP Phone 9951Cisco Unified IP Phone 997111/10/201316/6/2026
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
ModificadaMedia (5)2.1%—Cisco Unified IP Phones 9900 Series FirmwareCisco Unified IP Phone 9951Cisco Unified IP Phone 997111/10/201316/6/2026
Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.
ModificadaAlta (7.1)1.8%—Cisco Unified IP Phone 9951Cisco Unified IP Phone 997110/10/201316/6/2026
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.
ModificadaAlta (7.8)3.2%—Cisco Unified IP Phone 8945Cisco Unified IP Phone Firmware29/8/201316/6/2026
The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270.
ModificadaMedia (5)1.2%—Cisco Unified IP Phones 9900 Series FirmwareCisco Unified IP Phone 9951Cisco Unified IP Phone 997118/7/201316/6/2026
The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.
ModificadaMedia (6.8)0.40%—Cisco Skinny Client Control Protocol SoftwareCisco Unified IP PhoneCisco Unified IP Phone 7906g28/12/201216/6/2026
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
ModificadaMedia (4.6)0.41%—Cisco Unified IP PhoneCisco Unified IP Phone Firmware3/5/201216/6/2026
Cisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, which allows local users to gain privileges via unspecified injected data, aka Bug ID CSCts32237.
ModificadaBaja (1.5)0.27%—Cisco Unified IP Phone 7906Cisco Unified IP Phone 7911gCisco Unified IP Phone 7931gCisco Unified IP Phone 7941g+112/6/201116/6/2026
Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.