Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.6% | — | Moog Exvf5c-2 FirmwareMoog Exvp7c2-3 Firmware | 21/8/2020 | 17/6/2026 | The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary without arguments; however, this can be… | |
| Modificada | Alta (7.5) | 1.2% | — | Moog Exvf5c-2 FirmwareMoog Exvp7c2-3 Firmware | 21/8/2020 | 17/6/2026 | Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols. | |
| Modificada | Crítica (9.1) | 1.9% | — | Moog Exvf5c-2 FirmwareMoog Exvp7c2-3 Firmware | 21/8/2020 | 17/6/2026 | Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request. | |
| Modificada | Crítica (9.8) | 2.2% | — | Moog Exvf5c-2 FirmwareMoog Exvp7c2-3 Firmware | 21/8/2020 | 17/6/2026 | The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute… |