NEC records
123 published records for vendor nec.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 26
- With a fix record
- 1.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')29
- CWE-287 Improper Authentication8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-20 Improper Input Validation5
The weakness classes this vendor ships most often: where to look.
CWEAll records
123 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-1999-0043No exploit | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Critical9.8 | — | 44.6% | Dec 4, 1996 |
51Plan | CVE-2020-17408No exploit | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | High7.5 | — | 69.3% | Sep 10, 2020 |
49Plan | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Critical10.0 | — | 29.0% | Apr 8, 1998 |
44Plan | CVE-2018-11741Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionIdnec · univerge sv9100 webpro firmware · CWE-200 | Critical9.8 | — | 17.9% | Dec 26, 2018 |
44Plan | CVE-1999-0208Proof of concept | rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.sgi · irix | Critical10.0 | — | 12.9% | Dec 12, 1995 |
43Plan | CVE-2018-11742Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Critical9.8 | — | 14.3% | Dec 26, 2018 |
42Plan | CVE-2002-2368No exploit | Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitranec · socks 5 · CWE-119 | Critical10.0 | — | 6.9% | Dec 31, 2002 |
41Plan | CVE-2020-10917No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.nec · esmpro manager · CWE-502 | Critical9.8 | — | 5.6% | Jul 22, 2020 |
41Plan | CVE-1999-0048No exploit | Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.debian · netkit | Critical10.0 | — | 3.1% | Jan 27, 1997 |
40Plan | CVE-2020-5633No exploit | Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,nec · baseboard management controller · CWE-287 | Critical9.8 | — | 3.2% | Jan 13, 2021 |
40Plan | CVE-2019-20025No exploit | Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with nec · sv9100 firmware · CWE-798 | Critical9.8 | — | 2.9% | Jul 29, 2020 |
40Plan | CVE-2021-20702No exploit | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Critical9.8 | — | 2.2% | Nov 2, 2021 |
40Plan | CVE-2021-20704No exploit | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fonec · clusterpro x · CWE-120 | Critical9.8 | — | 2.1% | Nov 2, 2021 |
40Plan | CVE-2021-20703No exploit | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Critical9.8 | — | 2.1% | Nov 2, 2021 |
40Plan | CVE-2021-20701No exploit | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Critical9.8 | — | 2.1% | Nov 2, 2021 |
40Plan | CVE-2021-20700No exploit | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Critical9.8 | — | 2.1% | Nov 2, 2021 |
40Plan | CVE-2020-5685No exploit | UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-ofnec · univerge sv9500 firmware · CWE-78 | Critical9.8 | — | 1.8% | Jan 13, 2021 |
39Monitor | CVE-2022-34822No exploit | Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinnec · expresscluster x · CWE-22 | Critical9.8 | — | 1.5% | Nov 8, 2022 |
39Monitor | CVE-2023-3741No exploit | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on thenec · itk-6dgs-1\(bk\)tel firmware · CWE-78 | Critical9.8 | — | 1.5% | Nov 29, 2023 |
39Monitor | CVE-2022-25621No exploit | UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1nec · univerge wa1020 firmware · CWE-78 | Critical9.8 | — | 1.4% | Mar 11, 2022 |
39Monitor | CVE-2019-20027No exploit | Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if innec · sv8100 firmware · CWE-287 | Critical9.8 | — | 1.4% | Jul 29, 2020 |
39Monitor | CVE-2021-20711No exploit | Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.nec · aterm wg2600hs firmware · CWE-78 | Critical9.8 | — | 1.4% | Apr 25, 2021 |
39Monitor | CVE-2022-34823No exploit | Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinec · expresscluster x · CWE-120 | Critical9.8 | — | 1.4% | Nov 8, 2022 |
39Monitor | CVE-2022-34825No exploit | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Critical9.8 | — | 1.3% | Nov 8, 2022 |
39Monitor | CVE-2022-34824No exploit | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLnec · expresscluster x · CWE-276 | Critical9.8 | — | 1.2% | Nov 8, 2022 |
- CVE-1999-004352Plan
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CriticalCVSS 9.8No exploitEPSS 45%isc · innDec 4, 1996
- CVE-2020-1740851Plan
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
HighCVSS 7.5No exploitEPSS 69%nec · expresscluster xSep 10, 2020
- CVE-1999-000949Plan
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CriticalCVSS 10.0Proof of conceptEPSS 29%data general · dg uxApr 8, 1998
- CVE-2018-1174144Plan
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId
CriticalCVSS 9.8Proof of conceptEPSS 18%nec · univerge sv9100 webpro firmwareDec 26, 2018
- CVE-1999-020844Plan
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CriticalCVSS 10.0Proof of conceptEPSS 13%sgi · irixDec 12, 1995
- CVE-2018-1174243Plan
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
CriticalCVSS 9.8Proof of conceptEPSS 14%nec · univerge sv9100 webpro firmwareDec 26, 2018
- CVE-2002-236842Plan
Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitra
CriticalCVSS 10.0No exploitEPSS 7%nec · socks 5Dec 31, 2002
- CVE-2020-1091741Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.
CriticalCVSS 9.8No exploitEPSS 6%nec · esmpro managerJul 22, 2020
- CVE-1999-004841Plan
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
CriticalCVSS 10.0No exploitEPSS 3%debian · netkitJan 27, 1997
- CVE-2020-563340Plan
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,
CriticalCVSS 9.8No exploitEPSS 3%nec · baseboard management controllerJan 13, 2021
- CVE-2019-2002540Plan
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with
CriticalCVSS 9.8No exploitEPSS 3%nec · sv9100 firmwareJul 29, 2020
- CVE-2021-2070240Plan
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
CriticalCVSS 9.8No exploitEPSS 2%nec · clusterpro xNov 2, 2021
- CVE-2021-2070440Plan
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fo
CriticalCVSS 9.8No exploitEPSS 2%nec · clusterpro xNov 2, 2021
- CVE-2021-2070340Plan
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
CriticalCVSS 9.8No exploitEPSS 2%nec · clusterpro xNov 2, 2021
- CVE-2021-2070140Plan
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
CriticalCVSS 9.8No exploitEPSS 2%nec · clusterpro xNov 2, 2021
- CVE-2021-2070040Plan
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
CriticalCVSS 9.8No exploitEPSS 2%nec · clusterpro xNov 2, 2021
- CVE-2020-568540Plan
UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of
CriticalCVSS 9.8No exploitEPSS 2%nec · univerge sv9500 firmwareJan 13, 2021
- CVE-2022-3482239Monitor
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sin
CriticalCVSS 9.8No exploitEPSS 2%nec · expresscluster xNov 8, 2022
- CVE-2023-374139Monitor
An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the
CriticalCVSS 9.8No exploitEPSS 1%nec · itk-6dgs-1\(bk\)tel firmwareNov 29, 2023
- CVE-2022-2562139Monitor
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1
CriticalCVSS 9.8No exploitEPSS 1%nec · univerge wa1020 firmwareMar 11, 2022
- CVE-2019-2002739Monitor
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if in
CriticalCVSS 9.8No exploitEPSS 1%nec · sv8100 firmwareJul 29, 2020
- CVE-2021-2071139Monitor
Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
CriticalCVSS 9.8No exploitEPSS 1%nec · aterm wg2600hs firmwareApr 25, 2021
- CVE-2022-3482339Monitor
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Si
CriticalCVSS 9.8No exploitEPSS 1%nec · expresscluster xNov 8, 2022
- CVE-2022-3482539Monitor
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
CriticalCVSS 9.8No exploitEPSS 1%nec · expresscluster xNov 8, 2022
- CVE-2022-3482439Monitor
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CL
CriticalCVSS 9.8No exploitEPSS 1%nec · expresscluster xNov 8, 2022