Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)0.34%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+337/5/202617/6/2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
AnalizadaAlta (8.8)0.76%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
ModificadaMedia (5.7)0.41%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which…
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+2610/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
ModificadaAlta (8.1)0.52%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
ModificadaAlta (8.8)0.56%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
AnalizadaAlta (8.8)0.56%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard devices.
AnalizadaAlta (8.8)0.74%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable EMAIL_NOTIFICATION.TO in mGuard devices.
AnalizadaAlta (8.8)0.74%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable PROXY_HTTP_PORT in mGuard devices.
AnalizadaMedia (5.3)0.48%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact TC Mguard Rs4000 3G VPN Firmware+3210/9/202417/6/2026
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.
ModificadaMedia (5.3)0.62%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+2213/6/202317/6/2026
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
ModificadaAlta (7.5)0.91%—Phoenixcontact FL Mguard Centerport FirmwarePhoenixcontact FL Mguard Centerport Vpn-1000 FirmwarePhoenixcontact FL Mguard Core TX FirmwarePhoenixcontact FL Mguard Core TX VPN Firmware+2715/11/202217/6/2026
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.
ModificadaAlta (9.3)4.5%—Checkpoint Connectra NGXCheckpoint Vpn-1Checkpoint Vpn-1 Firewall-1 VSX5/10/201116/6/2026
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra, and VSX, allow remote attackers to execute arbitrary code via vectors involving a (1) ActiveX control or (2) Java applet.
ModificadaMedia (5)1.6%—Checkpoint Vpn-16/1/200916/6/2026
Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an…
ModificadaMedia (6.5)2.2%—Checkpoint Check Point Vpn-1 PROCheckpoint Vpn-1Checkpoint Vpn-1 Firewall-1Checkpoint Vpn-1 Power UTM+120/3/200816/6/2026
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP…
ModificadaMedia (4.3)1.9%—Checkpoint Vpn-1 UTM Edge W Embedded NGX8/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.
ModificadaAlta (7.8)0.34%—Checkpoint Vpn-1 Secureclient8/2/200816/6/2026
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.
ModificadaAlta (9.3)3.3%—Checkpoint Vpn-1 UTM Edge29/6/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters,…
ModificadaAlta (7.2)0.34%—Checkpoint Vpn-118/1/200616/6/2026
Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.
ModificadaMedia (6.5)3.1%—Checkpoint Secureclient NGCheckpoint Vpn-1 Secureclient8/12/200516/6/2026
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.
ModificadaAlta (7.8)4.9%—Checkpoint Check PointCheckpoint ExpressCheckpoint Firewall-1Checkpoint Vpn-1+118/11/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666,…
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.