Записи NEC
123 опубликованных записей вендора nec.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 1,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')29
- CWE-287 Improper Authentication8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-20 Improper Input Validation5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
123 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-1999-0043Эксплойта нет | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Критическая9,8 | — | 44,6 % | 4 дек. 1996 г. |
51В плане | CVE-2020-17408Эксплойта нет | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | Высокая7,5 | — | 69,3 % | 10 сент. 2020 г. |
49В плане | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Критическая10,0 | — | 29,0 % | 8 апр. 1998 г. |
44В плане | CVE-2018-11741Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionIdnec · univerge sv9100 webpro firmware · CWE-200 | Критическая9,8 | — | 17,9 % | 26 дек. 2018 г. |
44В плане | CVE-1999-0208Proof of concept | rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.sgi · irix | Критическая10,0 | — | 12,9 % | 12 дек. 1995 г. |
43В плане | CVE-2018-11742Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Критическая9,8 | — | 14,3 % | 26 дек. 2018 г. |
42В плане | CVE-2002-2368Эксплойта нет | Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitranec · socks 5 · CWE-119 | Критическая10,0 | — | 6,9 % | 31 дек. 2002 г. |
41В плане | CVE-2020-10917Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.nec · esmpro manager · CWE-502 | Критическая9,8 | — | 5,6 % | 22 июл. 2020 г. |
41В плане | CVE-1999-0048Эксплойта нет | Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.debian · netkit | Критическая10,0 | — | 3,1 % | 27 янв. 1997 г. |
40В плане | CVE-2020-5633Эксплойта нет | Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,nec · baseboard management controller · CWE-287 | Критическая9,8 | — | 3,2 % | 13 янв. 2021 г. |
40В плане | CVE-2019-20025Эксплойта нет | Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with nec · sv9100 firmware · CWE-798 | Критическая9,8 | — | 2,9 % | 29 июл. 2020 г. |
40В плане | CVE-2021-20702Эксплойта нет | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Критическая9,8 | — | 2,2 % | 2 нояб. 2021 г. |
40В плане | CVE-2021-20704Эксплойта нет | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fonec · clusterpro x · CWE-120 | Критическая9,8 | — | 2,1 % | 2 нояб. 2021 г. |
40В плане | CVE-2021-20703Эксплойта нет | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Критическая9,8 | — | 2,1 % | 2 нояб. 2021 г. |
40В плане | CVE-2021-20701Эксплойта нет | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Критическая9,8 | — | 2,1 % | 2 нояб. 2021 г. |
40В плане | CVE-2021-20700Эксплойта нет | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Критическая9,8 | — | 2,1 % | 2 нояб. 2021 г. |
40В плане | CVE-2020-5685Эксплойта нет | UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-ofnec · univerge sv9500 firmware · CWE-78 | Критическая9,8 | — | 1,8 % | 13 янв. 2021 г. |
39Наблюдать | CVE-2022-34822Эксплойта нет | Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinnec · expresscluster x · CWE-22 | Критическая9,8 | — | 1,5 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2023-3741Эксплойта нет | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on thenec · itk-6dgs-1\(bk\)tel firmware · CWE-78 | Критическая9,8 | — | 1,5 % | 29 нояб. 2023 г. |
39Наблюдать | CVE-2022-25621Эксплойта нет | UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1nec · univerge wa1020 firmware · CWE-78 | Критическая9,8 | — | 1,4 % | 11 мар. 2022 г. |
39Наблюдать | CVE-2019-20027Эксплойта нет | Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if innec · sv8100 firmware · CWE-287 | Критическая9,8 | — | 1,4 % | 29 июл. 2020 г. |
39Наблюдать | CVE-2021-20711Эксплойта нет | Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.nec · aterm wg2600hs firmware · CWE-78 | Критическая9,8 | — | 1,4 % | 25 апр. 2021 г. |
39Наблюдать | CVE-2022-34823Эксплойта нет | Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinec · expresscluster x · CWE-120 | Критическая9,8 | — | 1,4 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2022-34825Эксплойта нет | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Критическая9,8 | — | 1,3 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2022-34824Эксплойта нет | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLnec · expresscluster x · CWE-276 | Критическая9,8 | — | 1,2 % | 8 нояб. 2022 г. |
- CVE-1999-004352В плане
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %isc · inn4 дек. 1996 г.
- CVE-2020-1740851В плане
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %nec · expresscluster x10 сент. 2020 г.
- CVE-1999-000949В плане
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
КритическаяCVSS 10,0Proof of conceptEPSS 29 %data general · dg ux8 апр. 1998 г.
- CVE-2018-1174144В плане
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId
КритическаяCVSS 9,8Proof of conceptEPSS 18 %nec · univerge sv9100 webpro firmware26 дек. 2018 г.
- CVE-1999-020844В плане
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
КритическаяCVSS 10,0Proof of conceptEPSS 13 %sgi · irix12 дек. 1995 г.
- CVE-2018-1174243В плане
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
КритическаяCVSS 9,8Proof of conceptEPSS 14 %nec · univerge sv9100 webpro firmware26 дек. 2018 г.
- CVE-2002-236842В плане
Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitra
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %nec · socks 531 дек. 2002 г.
- CVE-2020-1091741В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %nec · esmpro manager22 июл. 2020 г.
- CVE-1999-004841В плане
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %debian · netkit27 янв. 1997 г.
- CVE-2020-563340В плане
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nec · baseboard management controller13 янв. 2021 г.
- CVE-2019-2002540В плане
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nec · sv9100 firmware29 июл. 2020 г.
- CVE-2021-2070240В плане
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · clusterpro x2 нояб. 2021 г.
- CVE-2021-2070440В плане
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fo
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · clusterpro x2 нояб. 2021 г.
- CVE-2021-2070340В плане
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · clusterpro x2 нояб. 2021 г.
- CVE-2021-2070140В плане
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · clusterpro x2 нояб. 2021 г.
- CVE-2021-2070040В плане
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · clusterpro x2 нояб. 2021 г.
- CVE-2020-568540В плане
UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · univerge sv9500 firmware13 янв. 2021 г.
- CVE-2022-3482239Наблюдать
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sin
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nec · expresscluster x8 нояб. 2022 г.
- CVE-2023-374139Наблюдать
An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · itk-6dgs-1\(bk\)tel firmware29 нояб. 2023 г.
- CVE-2022-2562139Наблюдать
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · univerge wa1020 firmware11 мар. 2022 г.
- CVE-2019-2002739Наблюдать
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if in
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · sv8100 firmware29 июл. 2020 г.
- CVE-2021-2071139Наблюдать
Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · aterm wg2600hs firmware25 апр. 2021 г.
- CVE-2022-3482339Наблюдать
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Si
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · expresscluster x8 нояб. 2022 г.
- CVE-2022-3482539Наблюдать
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · expresscluster x8 нояб. 2022 г.
- CVE-2022-3482439Наблюдать
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CL
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nec · expresscluster x8 нояб. 2022 г.