Записи Arris
28 опубликованных записей вендора arris.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 10,7 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-255 Credentials Management Errors3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2014-8423Готовый эксплойт | Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands viaarris · vap2500 firmware · CWE-74 | Критическая10,0 | — | 62,5 % | 28 нояб. 2014 г. |
49В плане | CVE-2014-8424Готовый эксплойт | ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.arris · vap2500 firmware · CWE-287 | Высокая7,8 | — | 59,6 % | 28 нояб. 2014 г. |
41В плане | CVE-2014-9406Эксплойта нет | ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account, arris · touchstone tg862g\/ct firmware · CWE-255 | Критическая10,0 | — | 2,1 % | 18 дек. 2014 г. |
40В плане | CVE-2022-26994Эксплойта нет | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Критическая9,8 | — | 3,0 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26992Эксплойта нет | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Критическая9,8 | — | 2,9 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26990Эксплойта нет | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Критическая9,8 | — | 2,9 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26991Эксплойта нет | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Критическая9,8 | — | 2,7 % | 15 мар. 2022 г. |
40В плане | CVE-2022-26993Эксплойта нет | Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerabarris · sbr-ac1900p firmware · CWE-78 | Критическая9,8 | — | 2,7 % | 15 мар. 2022 г. |
40В плане | CVE-2018-20383Эксплойта нет | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0arris · dg950s firmware · CWE-522 | Критическая9,8 | — | 1,8 % | 23 дек. 2018 г. |
39Наблюдать | CVE-2023-40039Эксплойта нет | An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices.arris · tg852g firmware · CWE-284 | Критическая9,8 | — | 1,2 % | 11 сент. 2023 г. |
38Наблюдать | CVE-2015-7289Эксплойта нет | Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password dearris · na model 862 gw mono firmware · CWE-255 | Критическая9,3 | — | 2,1 % | 21 нояб. 2015 г. |
35Наблюдать | CVE-2022-31793Proof of concept | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single characteinglorion · muhttpd · CWE-22 | Высокая7,5 | — | 16,9 % | 4 авг. 2022 г. |
35Наблюдать | CVE-2017-9490Эксплойта нет | The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows coarris · tg1682g firmware · CWE-352 | Высокая8,8 | — | 0,5 % | 30 июл. 2017 г. |
35Наблюдать | CVE-2024-25729Эксплойта нет | Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access.CWE-521 | Высокая8,8 | — | 0,5 % | 7 мар. 2024 г. |
35Наблюдать | CVE-2023-40038Эксплойта нет | Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access.arris · dg860a firmware · CWE-287 | Высокая8,8 | — | 0,4 % | 27 дек. 2023 г. |
32Наблюдать | CVE-2014-8425Proof of concept | The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.arris · vap2500 firmware · CWE-200 | Высокая7,8 | — | 3,1 % | 28 нояб. 2014 г. |
32Наблюдать | CVE-2007-2796Эксплойта нет | Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IParris · cadant c3 cmts | Высокая7,8 | — | 2,2 % | 12 июн. 2007 г. |
28Наблюдать | CVE-2020-8438Эксплойта нет | Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHarris · ruckus zoneflex r500 firmware · CWE-78 | Высокая7,2 | — | 1,6 % | 29 янв. 2020 г. |
27Наблюдать | CVE-2024-5195Эксплойта нет | Arris VAP2500 diag_s.php command injectionarris · vap2500 firmware · CWE-77 | Средняя5,1 | — | 23,4 % | 22 мая 2024 г. |
27Наблюдать | CVE-2024-5196Эксплойта нет | Arris VAP2500 tools_command.php command injectionarris · vap2500 firmware · CWE-77 | Средняя5,1 | — | 23,4 % | 22 мая 2024 г. |
27Наблюдать | CVE-2015-7291Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices warris · na model 862 gw mono firmware · CWE-352 | Средняя6,8 | — | 1,0 % | 21 нояб. 2015 г. |
27Наблюдать | CVE-2014-5437Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlarris · touchstone tg862g\/ct firmware · CWE-352 | Средняя6,8 | — | 0,6 % | 17 дек. 2014 г. |
25Наблюдать | CVE-2014-4863Готовый эксплойт | The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensarris · touchstone dg950a software · CWE-200 | Средняя5,0 | — | 15,7 % | 5 сент. 2014 г. |
24Наблюдать | CVE-2022-45028Эксплойта нет | A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a craftarris · nvg443b firmware · CWE-79 | Средняя6,1 | — | 0,5 % | 13 дек. 2022 г. |
21Наблюдать | CVE-2024-5194Эксплойта нет | Arris VAP2500 assoc_table.php command injectionarris · vap2500 firmware · CWE-77 | Средняя5,1 | — | 3,6 % | 22 мая 2024 г. |
- CVE-2014-842359В плане
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via
КритическаяCVSS 10,0Готовый эксплойтEPSS 62 %arris · vap2500 firmware28 нояб. 2014 г.
- CVE-2014-842449В плане
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
ВысокаяCVSS 7,8Готовый эксплойтEPSS 60 %arris · vap2500 firmware28 нояб. 2014 г.
- CVE-2014-940641В плане
ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account,
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %arris · touchstone tg862g\/ct firmware18 дек. 2014 г.
- CVE-2022-2699440В плане
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arris · sbr-ac1900p firmware15 мар. 2022 г.
- CVE-2022-2699240В плане
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arris · sbr-ac1900p firmware15 мар. 2022 г.
- CVE-2022-2699040В плане
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arris · sbr-ac1900p firmware15 мар. 2022 г.
- CVE-2022-2699140В плане
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arris · sbr-ac1900p firmware15 мар. 2022 г.
- CVE-2022-2699340В плане
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerab
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arris · sbr-ac1900p firmware15 мар. 2022 г.
- CVE-2018-2038340В плане
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %arris · dg950s firmware23 дек. 2018 г.
- CVE-2023-4003939Наблюдать
An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arris · tg852g firmware11 сент. 2023 г.
- CVE-2015-728938Наблюдать
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password de
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %arris · na model 862 gw mono firmware21 нояб. 2015 г.
- CVE-2022-3179335Наблюдать
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single characte
ВысокаяCVSS 7,5Proof of conceptEPSS 17 %inglorion · muhttpd4 авг. 2022 г.
- CVE-2017-949035Наблюдать
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows co
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %arris · tg1682g firmware30 июл. 2017 г.
- CVE-2024-2572935Наблюдать
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %7 мар. 2024 г.
- CVE-2023-4003835Наблюдать
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %arris · dg860a firmware27 дек. 2023 г.
- CVE-2014-842532Наблюдать
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %arris · vap2500 firmware28 нояб. 2014 г.
- CVE-2007-279632Наблюдать
Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %arris · cadant c3 cmts12 июн. 2007 г.
- CVE-2020-843828Наблюдать
Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupH
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %arris · ruckus zoneflex r500 firmware29 янв. 2020 г.
- CVE-2024-519527Наблюдать
Arris VAP2500 diag_s.php command injection
СредняяCVSS 5,1Эксплойта нетEPSS 23 %arris · vap2500 firmware22 мая 2024 г.
- CVE-2024-519627Наблюдать
Arris VAP2500 tools_command.php command injection
СредняяCVSS 5,1Эксплойта нетEPSS 23 %arris · vap2500 firmware22 мая 2024 г.
- CVE-2015-729127Наблюдать
Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices w
СредняяCVSS 6,8Эксплойта нетEPSS 1 %arris · na model 862 gw mono firmware21 нояб. 2015 г.
- CVE-2014-543727Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earl
СредняяCVSS 6,8Эксплойта нетEPSS 1 %arris · touchstone tg862g\/ct firmware17 дек. 2014 г.
- CVE-2014-486325Наблюдать
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sens
СредняяCVSS 5,0Готовый эксплойтEPSS 16 %arris · touchstone dg950a software5 сент. 2014 г.
- CVE-2022-4502824Наблюдать
A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a craft
СредняяCVSS 6,1Эксплойта нетEPSS 1 %arris · nvg443b firmware13 дек. 2022 г.
- CVE-2024-519421Наблюдать
Arris VAP2500 assoc_table.php command injection
СредняяCVSS 5,1Эксплойта нетEPSS 4 %arris · vap2500 firmware22 мая 2024 г.