NEC kayıtları
nec üreticisine ait 123 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %1,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')29
- CWE-287 Improper Authentication8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-20 Improper Input Validation5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
123 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-1999-0043İstismar yok | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Kritik9,8 | — | %44,6 | 4 Ara 1996 |
51Planlayın | CVE-2020-17408İstismar yok | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | Yüksek7,5 | — | %69,3 | 10 Eyl 2020 |
49Planlayın | CVE-1999-0009Kavram kanıtı | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Kritik10,0 | — | %29,0 | 8 Nis 1998 |
44Planlayın | CVE-2018-11741Kavram kanıtı | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionIdnec · univerge sv9100 webpro firmware · CWE-200 | Kritik9,8 | — | %17,9 | 26 Ara 2018 |
44Planlayın | CVE-1999-0208Kavram kanıtı | rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.sgi · irix | Kritik10,0 | — | %12,9 | 12 Ara 1995 |
43Planlayın | CVE-2018-11742Kavram kanıtı | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Kritik9,8 | — | %14,3 | 26 Ara 2018 |
42Planlayın | CVE-2002-2368İstismar yok | Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitranec · socks 5 · CWE-119 | Kritik10,0 | — | %6,9 | 31 Ara 2002 |
41Planlayın | CVE-2020-10917İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.nec · esmpro manager · CWE-502 | Kritik9,8 | — | %5,6 | 22 Tem 2020 |
41Planlayın | CVE-1999-0048İstismar yok | Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.debian · netkit | Kritik10,0 | — | %3,1 | 27 Oca 1997 |
40Planlayın | CVE-2020-5633İstismar yok | Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,nec · baseboard management controller · CWE-287 | Kritik9,8 | — | %3,2 | 13 Oca 2021 |
40Planlayın | CVE-2019-20025İstismar yok | Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with nec · sv9100 firmware · CWE-798 | Kritik9,8 | — | %2,9 | 29 Tem 2020 |
40Planlayın | CVE-2021-20702İstismar yok | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Kritik9,8 | — | %2,2 | 2 Kas 2021 |
40Planlayın | CVE-2021-20704İstismar yok | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fonec · clusterpro x · CWE-120 | Kritik9,8 | — | %2,1 | 2 Kas 2021 |
40Planlayın | CVE-2021-20703İstismar yok | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlinec · clusterpro x · CWE-120 | Kritik9,8 | — | %2,1 | 2 Kas 2021 |
40Planlayın | CVE-2021-20701İstismar yok | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Kritik9,8 | — | %2,1 | 2 Kas 2021 |
40Planlayın | CVE-2021-20700İstismar yok | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSnec · clusterpro x · CWE-120 | Kritik9,8 | — | %2,1 | 2 Kas 2021 |
40Planlayın | CVE-2020-5685İstismar yok | UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-ofnec · univerge sv9500 firmware · CWE-78 | Kritik9,8 | — | %1,8 | 13 Oca 2021 |
39İzleyin | CVE-2022-34822İstismar yok | Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinnec · expresscluster x · CWE-22 | Kritik9,8 | — | %1,5 | 8 Kas 2022 |
39İzleyin | CVE-2023-3741İstismar yok | An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on thenec · itk-6dgs-1\(bk\)tel firmware · CWE-78 | Kritik9,8 | — | %1,5 | 29 Kas 2023 |
39İzleyin | CVE-2022-25621İstismar yok | UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1nec · univerge wa1020 firmware · CWE-78 | Kritik9,8 | — | %1,4 | 11 Mar 2022 |
39İzleyin | CVE-2019-20027İstismar yok | Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if innec · sv8100 firmware · CWE-287 | Kritik9,8 | — | %1,4 | 29 Tem 2020 |
39İzleyin | CVE-2021-20711İstismar yok | Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.nec · aterm wg2600hs firmware · CWE-78 | Kritik9,8 | — | %1,4 | 25 Nis 2021 |
39İzleyin | CVE-2022-34823İstismar yok | Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sinec · expresscluster x · CWE-120 | Kritik9,8 | — | %1,4 | 8 Kas 2022 |
39İzleyin | CVE-2022-34825İstismar yok | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0nec · expresscluster x · CWE-427 | Kritik9,8 | — | %1,3 | 8 Kas 2022 |
39İzleyin | CVE-2022-34824İstismar yok | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLnec · expresscluster x · CWE-276 | Kritik9,8 | — | %1,2 | 8 Kas 2022 |
- CVE-1999-004352Planlayın
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
KritikCVSS 9,8İstismar yokEPSS %45isc · inn4 Ara 1996
- CVE-2020-1740851Planlayın
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
YüksekCVSS 7,5İstismar yokEPSS %69nec · expresscluster x10 Eyl 2020
- CVE-1999-000949Planlayın
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
KritikCVSS 10,0Kavram kanıtıEPSS %29data general · dg ux8 Nis 1998
- CVE-2018-1174144Planlayın
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId
KritikCVSS 9,8Kavram kanıtıEPSS %18nec · univerge sv9100 webpro firmware26 Ara 2018
- CVE-1999-020844Planlayın
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
KritikCVSS 10,0Kavram kanıtıEPSS %13sgi · irix12 Ara 1995
- CVE-2018-1174243Planlayın
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
KritikCVSS 9,8Kavram kanıtıEPSS %14nec · univerge sv9100 webpro firmware26 Ara 2018
- CVE-2002-236842Planlayın
Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitra
KritikCVSS 10,0İstismar yokEPSS %7nec · socks 531 Ara 2002
- CVE-2020-1091741Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42.
KritikCVSS 9,8İstismar yokEPSS %6nec · esmpro manager22 Tem 2020
- CVE-1999-004841Planlayın
Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.
KritikCVSS 10,0İstismar yokEPSS %3debian · netkit27 Oca 1997
- CVE-2020-563340Planlayın
Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti,
KritikCVSS 9,8İstismar yokEPSS %3nec · baseboard management controller13 Oca 2021
- CVE-2019-2002540Planlayın
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with
KritikCVSS 9,8İstismar yokEPSS %3nec · sv9100 firmware29 Tem 2020
- CVE-2021-2070240Planlayın
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
KritikCVSS 9,8İstismar yokEPSS %2nec · clusterpro x2 Kas 2021
- CVE-2021-2070440Planlayın
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 fo
KritikCVSS 9,8İstismar yokEPSS %2nec · clusterpro x2 Kas 2021
- CVE-2021-2070340Planlayın
Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earli
KritikCVSS 9,8İstismar yokEPSS %2nec · clusterpro x2 Kas 2021
- CVE-2021-2070140Planlayın
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
KritikCVSS 9,8İstismar yokEPSS %2nec · clusterpro x2 Kas 2021
- CVE-2021-2070040Planlayın
Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUS
KritikCVSS 9,8İstismar yokEPSS %2nec · clusterpro x2 Kas 2021
- CVE-2020-568540Planlayın
UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of
KritikCVSS 9,8İstismar yokEPSS %2nec · univerge sv9500 firmware13 Oca 2021
- CVE-2022-3482239İzleyin
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Sin
KritikCVSS 9,8İstismar yokEPSS %2nec · expresscluster x8 Kas 2022
- CVE-2023-374139İzleyin
An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the
KritikCVSS 9,8İstismar yokEPSS %1nec · itk-6dgs-1\(bk\)tel firmware29 Kas 2023
- CVE-2022-2562139İzleyin
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.1
KritikCVSS 9,8İstismar yokEPSS %1nec · univerge wa1020 firmware11 Mar 2022
- CVE-2019-2002739İzleyin
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if in
KritikCVSS 9,8İstismar yokEPSS %1nec · sv8100 firmware29 Tem 2020
- CVE-2021-2071139İzleyin
Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
KritikCVSS 9,8İstismar yokEPSS %1nec · aterm wg2600hs firmware25 Nis 2021
- CVE-2022-3482339İzleyin
Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 Si
KritikCVSS 9,8İstismar yokEPSS %1nec · expresscluster x8 Kas 2022
- CVE-2022-3482539İzleyin
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0
KritikCVSS 9,8İstismar yokEPSS %1nec · expresscluster x8 Kas 2022
- CVE-2022-3482439İzleyin
Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CL
KritikCVSS 9,8İstismar yokEPSS %1nec · expresscluster x8 Kas 2022