Записи Verizon
21 опубликованных записей вендора verizon.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 9,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-287 Improper Authentication4
- CWE-521 Weak Password Requirements2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-425 Direct Request ('Forced Browsing')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-28375Эксплойта нет | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile fverizon · lvskihp outdoorunit firmware · CWE-78 | Критическая9,8 | — | 2,3 % | 14 июл. 2022 г. |
40В плане | CVE-2022-28373Эксплойта нет | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition functverizon · lvskihp indoorunit firmware · CWE-78 | Критическая9,8 | — | 2,3 % | 14 июл. 2022 г. |
39Наблюдать | CVE-2022-28369Эксплойта нет | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-opverizon · lvskihp indoorunit firmware · CWE-434 | Критическая9,8 | — | 1,5 % | 14 июл. 2022 г. |
37Наблюдать | CVE-2019-3914Эксплойта нет | Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated averizon · fios quantum gateway g1100 firmware · CWE-78 | Высокая7,2 | — | 29,9 % | 11 апр. 2019 г. |
36Наблюдать | CVE-2022-28374Эксплойта нет | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settverizon · lvskihp outdoorunit firmware · CWE-78 | Высокая8,8 | — | 2,4 % | 14 июл. 2022 г. |
33Наблюдать | CVE-2020-7660Эксплойта нет | serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".verizon · serialize-javascript · CWE-502 | Высокая8,1 | — | 3,0 % | 1 июн. 2020 г. |
32Наблюдать | CVE-2022-28376Эксплойта нет | Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, verizon · lvskihp firmware · CWE-287 | Высокая8,1 | — | 1,2 % | 3 апр. 2022 г. |
31Наблюдать | CVE-2019-3916Эксплойта нет | Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated verizon · fios quantum gateway g1100 firmware · CWE-425 | Высокая7,5 | — | 2,1 % | 11 апр. 2019 г. |
30Наблюдать | CVE-2022-29729Эксплойта нет | Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwordsverizon · 4g lte network extender firmware · CWE-521 | Высокая7,5 | — | 1,5 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2022-28377Эксплойта нет | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a stverizon · lvskihp indoorunit firmware · CWE-521 | Высокая7,5 | — | 1,0 % | 14 июл. 2022 г. |
30Наблюдать | CVE-2022-28372Эксплойта нет | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a meverizon · lvskihp indoorunit firmware · CWE-434 | Высокая7,5 | — | 0,8 % | 14 июл. 2022 г. |
30Наблюдать | CVE-2019-3915Эксплойта нет | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unautheverizon · fios quantum gateway g1100 firmware · CWE-294 | Высокая7,5 | — | 0,6 % | 11 апр. 2019 г. |
30Наблюдать | CVE-2022-28371Эксплойта нет | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a stverizon · lvskihp indoorunit firmware · CWE-798 | Высокая7,5 | — | 0,6 % | 14 июл. 2022 г. |
30Наблюдать | CVE-2022-28370Эксплойта нет | On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmwarverizon · lvskihp outdoorunit firmware · CWE-345 | Высокая7,5 | — | 0,4 % | 14 июл. 2022 г. |
28Наблюдать | CVE-2013-0126Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.verizon · fios actiontec mi424wr-gen31 router firmware · CWE-352 | Средняя6,8 | — | 2,9 % | 21 мар. 2013 г. |
24Наблюдать | CVE-2013-4875Эксплойта нет | The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot proverizon · wireless network extender · CWE-287 | Средняя6,2 | — | 0,7 % | 18 июл. 2013 г. |
24Наблюдать | CVE-2013-4876Эксплойта нет | The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximateverizon · wireless network extender · CWE-255 | Средняя6,2 | — | 0,7 % | 18 июл. 2013 г. |
24Наблюдать | CVE-2013-4874Эксплойта нет | The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by conneverizon · wireless network extender · CWE-287 | Средняя6,2 | — | 0,7 % | 18 июл. 2013 г. |
21Наблюдать | CVE-2019-16769Эксплойта нет | Affected versions of serialize-javascript are vulnerable to Cross-site Scripting (XSS)verizon · serialize-javascript · CWE-79 | Средняя5,4 | — | 0,8 % | 5 дек. 2019 г. |
13Наблюдать | CVE-2023-38301Эксплойта нет | An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers.CWE-200 | Низкая3,4 | — | 0,2 % | 22 апр. 2024 г. |
10Наблюдать | CVE-2013-4877Эксплойта нет | The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers toverizon · wireless network extender · CWE-287 | Низкая2,6 | — | 0,8 % | 18 июл. 2013 г. |
- CVE-2022-2837540В плане
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile f
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %verizon · lvskihp outdoorunit firmware14 июл. 2022 г.
- CVE-2022-2837340В плане
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition funct
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %verizon · lvskihp indoorunit firmware14 июл. 2022 г.
- CVE-2022-2836939Наблюдать
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-op
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %verizon · lvskihp indoorunit firmware14 июл. 2022 г.
- CVE-2019-391437Наблюдать
Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated a
ВысокаяCVSS 7,2Эксплойта нетEPSS 30 %verizon · fios quantum gateway g1100 firmware11 апр. 2019 г.
- CVE-2022-2837436Наблюдать
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Sett
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %verizon · lvskihp outdoorunit firmware14 июл. 2022 г.
- CVE-2020-766033Наблюдать
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %verizon · serialize-javascript1 июн. 2020 г.
- CVE-2022-2837632Наблюдать
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website,
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %verizon · lvskihp firmware3 апр. 2022 г.
- CVE-2019-391631Наблюдать
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %verizon · fios quantum gateway g1100 firmware11 апр. 2019 г.
- CVE-2022-2972930Наблюдать
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verizon · 4g lte network extender firmware2 июн. 2022 г.
- CVE-2022-2837730Наблюдать
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a st
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verizon · lvskihp indoorunit firmware14 июл. 2022 г.
- CVE-2022-2837230Наблюдать
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a me
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verizon · lvskihp indoorunit firmware14 июл. 2022 г.
- CVE-2019-391530Наблюдать
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthe
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verizon · fios quantum gateway g1100 firmware11 апр. 2019 г.
- CVE-2022-2837130Наблюдать
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a st
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %verizon · lvskihp indoorunit firmware14 июл. 2022 г.
- CVE-2022-2837030Наблюдать
On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of provisioning a firmwar
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %verizon · lvskihp outdoorunit firmware14 июл. 2022 г.
- CVE-2013-012628Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.
СредняяCVSS 6,8Proof of conceptEPSS 3 %verizon · fios actiontec mi424wr-gen31 router firmware21 мар. 2013 г.
- CVE-2013-487524Наблюдать
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot pro
СредняяCVSS 6,2Эксплойта нетEPSS 1 %verizon · wireless network extender18 июл. 2013 г.
- CVE-2013-487624Наблюдать
The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximate
СредняяCVSS 6,2Эксплойта нетEPSS 1 %verizon · wireless network extender18 июл. 2013 г.
- CVE-2013-487424Наблюдать
The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by conne
СредняяCVSS 6,2Эксплойта нетEPSS 1 %verizon · wireless network extender18 июл. 2013 г.
- CVE-2019-1676921Наблюдать
Affected versions of serialize-javascript are vulnerable to Cross-site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 1 %verizon · serialize-javascript5 дек. 2019 г.
- CVE-2023-3830113Наблюдать
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers.
НизкаяCVSS 3,4Эксплойта нетEPSS 0 %22 апр. 2024 г.
- CVE-2013-487710Наблюдать
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to
НизкаяCVSS 2,6Эксплойта нетEPSS 1 %verizon · wireless network extender18 июл. 2013 г.