Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | Cisco ASA 5500Cisco PIX 500Cisco VPN 3000 ConcentratorCisco VPN 3005 Concentrator+5 | 30/11/2010 | 16/6/2026 | The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote… | |
| Modificada | Media (5) | 12% | — | Cisco VPN 3000 Concentrator Series Software | 23/8/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors. | |
| Modificada | Media (5) | 6.9% | — | Cisco IOSCisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 Concentrator+17 | 27/7/2006 | 16/6/2026 | Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a… | |
| Modificada | Baja (2.6) | 1.7% | — | Cisco ASA 5500Cisco VPN 3000 Concentrator Series Software | 19/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html… | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3030 Concentator | 31/1/2006 | 16/6/2026 | Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Media (5) | 2.3% | — | Cisco VPN 3000 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+4 | 20/6/2005 | 16/6/2026 | Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 Concentrator+4 | 30/3/2005 | 16/6/2026 | Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+3 | 27/5/2003 | 16/6/2026 | Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication. | |
| Modificada | Media (5) | 2.1% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+2 | 27/5/2003 | 16/6/2026 | Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets. | |
| Modificada | Media (5) | 2.1% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+2 | 27/5/2003 | 16/6/2026 | Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet. | |
| Modificada | Media (5) | 3.4% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | |
| Modificada | Media (5) | 1.4% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets. | |
| Modificada | Alta (7.5) | 1.1% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator. | |
| Modificada | Alta (7.5) | 1.4% | — | Cisco VPN 3000 Concentrator Series Software | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication. | |
| Modificada | Media (5) | 1.7% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous… | |
| Modificada | Media (5) | 1.5% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3000 Concentrator Series Software | 4/10/2002 | 16/6/2026 | HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code. | |
| Modificada | Media (5) | 1.0% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco Secure Access Control ServerCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client | 4/10/2002 | 16/6/2026 | Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request. | |
| Modificada | Media (5) | 1.7% | — | Cisco VPN 3000 Concentrator Series Software | 2/7/2001 | 16/6/2026 | Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option. |