Записи IETF
17 опубликованных записей вендора ietf.
Профиль для исследователя
- Попали в KEV
- 1 · 5,9 %
- С эксплойтом
- 1 · 5,9 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 23,5 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-290 Authentication Bypass by Spoofing4
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-130 Improper Handling of Length Parameter Inconsistency2
- CWE-940 Improper Verification of Source of a Communication Channel2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-521 Weak Password Requirements1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
42В плане | CVE-2004-2761Proof of concept | The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacietf · md5 · CWE-310 | Критическая9,8 | — | 9,9 % | 5 янв. 2009 г. |
35Наблюдать | CVE-2016-10142Эксплойта нет | An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.ietf · ipv6 · CWE-17 | Высокая8,6 | — | 2,8 % | 14 янв. 2017 г. |
33Наблюдать | CVE-2007-2242Эксплойта нет | The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that createopenbsd · openbsd | Высокая7,8 | — | 5,0 % | 25 апр. 2007 г. |
33Наблюдать | CVE-2015-8960Эксплойта нет | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateTietf · transport layer security · CWE-295 | Высокая8,1 | — | 1,9 % | 20 сент. 2016 г. |
26Наблюдать | CVE-2024-7595Proof of concept | GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packetietf · generic routing encapsulation · CWE-290 | Средняя6,5 | — | 1,6 % | 5 февр. 2025 г. |
26Наблюдать | CVE-2025-23018Эксплойта нет | IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowingietf · ipv6 · CWE-940 | Средняя6,5 | — | 1,0 % | 14 янв. 2025 г. |
26Наблюдать | CVE-2025-23019Эксплойта нет | IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.ietf · ipv6 · CWE-940 | Средняя6,5 | — | 1,0 % | 14 янв. 2025 г. |
26Наблюдать | CVE-2024-7596Эксплойта нет | Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packetietf · generic udp encapsulation · CWE-290 | Средняя6,5 | — | 0,9 % | 5 февр. 2025 г. |
24Наблюдать | CVE-2018-5389Эксплойта нет | The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks.ietf · internet key exchange · CWE-521 | Средняя5,9 | — | 3,0 % | 6 сент. 2018 г. |
23Наблюдать | CVE-2020-20949Эксплойта нет | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).st · stm32cubef0 · CWE-327 | Средняя5,9 | — | 0,9 % | 20 янв. 2021 г. |
23Наблюдать | CVE-2020-20950Эксплойта нет | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26.microchip · microchip libraries for applications · CWE-327 | Средняя5,9 | — | 0,9 % | 19 янв. 2021 г. |
18Наблюдать | CVE-2021-27853Эксплойта нет | L2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headersieee · ieee 802.2 · CWE-290 | Средняя4,7 | — | 0,8 % | 27 сент. 2022 г. |
18Наблюдать | CVE-2021-27854Эксплойта нет | L2 network filtering bypass using stacked VLAN0, LLC/SNAP headers, and Ethernet to Wifi frame translationieee · ieee 802.2 · CWE-290 | Средняя4,7 | — | 0,7 % | 27 сент. 2022 г. |
18Наблюдать | CVE-2021-27862Эксплойта нет | L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translationieee · ieee 802.2 · CWE-130 | Средняя4,7 | — | 0,7 % | 27 сент. 2022 г. |
18Наблюдать | CVE-2021-27861Эксплойта нет | L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengthsieee · ieee 802.2 · CWE-130 | Средняя4,7 | — | 0,7 % | 27 сент. 2022 г. |
17Наблюдать | CVE-2024-39920Эксплойта нет | The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection CWE-1255 | Средняя4,3 | — | 0,6 % | 3 июл. 2024 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2004-276142В плане
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac
КритическаяCVSS 9,8Proof of conceptEPSS 10 %ietf · md55 янв. 2009 г.
- CVE-2016-1014235Наблюдать
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %ietf · ipv614 янв. 2017 г.
- CVE-2007-224233Наблюдать
The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %openbsd · openbsd25 апр. 2007 г.
- CVE-2015-896033Наблюдать
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateT
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %ietf · transport layer security20 сент. 2016 г.
- CVE-2024-759526Наблюдать
GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet
СредняяCVSS 6,5Proof of conceptEPSS 2 %ietf · generic routing encapsulation5 февр. 2025 г.
- CVE-2025-2301826Наблюдать
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ietf · ipv614 янв. 2025 г.
- CVE-2025-2301926Наблюдать
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ietf · ipv614 янв. 2025 г.
- CVE-2024-759626Наблюдать
Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ietf · generic udp encapsulation5 февр. 2025 г.
- CVE-2018-538924Наблюдать
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %ietf · internet key exchange6 сент. 2018 г.
- CVE-2020-2094923Наблюдать
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).
СредняяCVSS 5,9Эксплойта нетEPSS 1 %st · stm32cubef020 янв. 2021 г.
- CVE-2020-2095023Наблюдать
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %microchip · microchip libraries for applications19 янв. 2021 г.
- CVE-2021-2785318Наблюдать
L2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headers
СредняяCVSS 4,7Эксплойта нетEPSS 1 %ieee · ieee 802.227 сент. 2022 г.
- CVE-2021-2785418Наблюдать
L2 network filtering bypass using stacked VLAN0, LLC/SNAP headers, and Ethernet to Wifi frame translation
СредняяCVSS 4,7Эксплойта нетEPSS 1 %ieee · ieee 802.227 сент. 2022 г.
- CVE-2021-2786218Наблюдать
L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translation
СредняяCVSS 4,7Эксплойта нетEPSS 1 %ieee · ieee 802.227 сент. 2022 г.
- CVE-2021-2786118Наблюдать
L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengths
СредняяCVSS 4,7Эксплойта нетEPSS 1 %ieee · ieee 802.227 сент. 2022 г.
- CVE-2024-3992017Наблюдать
The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection
СредняяCVSS 4,3Эксплойта нетEPSS 1 %3 июл. 2024 г.