Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.25%—Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI7/5/202517/6/2026
A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This…
AnalizadaAlta (7.4)0.29%—Cisco Wireless LAN Controller SoftwareCisco IOS XE27/3/202417/6/2026
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed…
AnalizadaAlta (8.6)0.63%—Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software27/3/202417/6/2026
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this…
ModificadaMedia (4.7)0.26%—Cisco Wireless LAN Controller SoftwareCisco Catalyst 9800 Embedded Wireless Controller FirmwareCisco Business 150ax FirmwareCisco Business 151axm Firmware27/9/202317/6/2026
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A…
ModificadaMedia (6.7)0.24%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator…
ModificadaMedia (5.5)0.26%—Cisco Wireless LAN Controller SoftwareCisco Aironet Access Point SoftwareCisco IOS XE23/3/202317/6/2026
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this…
ModificadaMedia (6.5)0.52%—Cisco Wireless LAN Controller Software30/9/202217/6/2026
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error validation. An attacker could exploit this…
ModificadaCrítica (10)20%—Cisco Wireless LAN Controller 8.10.151.0Cisco Wireless LAN Controller 8.10.162.015/4/202217/6/2026
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface This vulnerability is due to the improper implementation of the password…
ModificadaAlta (7.8)0.22%—Cisco Aironet 1542d FirmwareCisco Aironet 1562d FirmwareCisco Aironet 1815m FirmwareCisco Aironet 1830e Firmware+3723/9/202117/6/2026
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is due to improper checking on file operations within the SSH management interface. A…
ModificadaMedia (4.4)0.23%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An attacker could exploit this vulnerability…
ModificadaMedia (6.7)0.27%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit this vulnerability…
ModificadaAlta (7.5)1.5%—Cisco Aironet Access Point SoftwareCisco Catalyst 9800 FirmwareCisco Wireless LAN Controller Software24/3/202117/6/2026
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configuration. An attacker…
ModificadaAlta (8.6)1.4%—Cisco Wireless LAN ControllerCisco Wireless LAN Controller SoftwareCisco Business Access PointsCisco Access Points+124/9/202017/6/2026
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attacker could exploit this vulnerability by sending a series of…
ModificadaAlta (8.6)1.4%—Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software24/9/202017/6/2026
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could exploit this vulnerability by sending authentication…
ModificadaAlta (7.4)0.49%—Cisco Wireless LAN ControllerCisco Business Access PointsCisco Access PointsCisco Aironet Access Point Software24/9/202017/6/2026
A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…
ModificadaMedia (6.5)46%—Cisco Wireless LAN Controller Software26/11/201917/6/2026
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An…
ModificadaMedia (4.4)0.65%—Cisco Wireless LAN Controller Software16/10/201917/6/2026
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit…
ModificadaAlta (7.5)1.4%—Cisco 5520 Wireless LAN Controller FirmwareCisco 5508 Wireless LAN Controller Firmware16/10/201917/6/2026
A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is not properly deleted when an SSH…
ModificadaMedia (4.9)1.2%—Cisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) condition. The attacker would need to have valid administrator credentials.…
ModificadaMedia (4.3)0.55%—Cisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnerability is due to a lack of proper input- and…
ModificadaMedia (6.5)0.52%—Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP…
ModificadaMedia (6.5)0.65%—Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP…
ModificadaAlta (8.8)0.74%—Cisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device…
ModificadaMedia (6.5)0.65%—Cisco Wireless LAN ControllerCisco Wireless LAN Controller Software18/4/201917/6/2026
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP…
ModificadaAlta (7.5)2.0%—Cisco Wireless LAN Controller Software17/4/201917/6/2026
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The vulnerability exists because the affected software does not…