Vulnerabilidades em NEC Corporation

88 resultados
Análise Vexday

O portfólio de vulnerabilidades da NEC Corporation reúne 87 CVEs catalogadas, com 13 classificadas como críticas, mas apresenta indicadores de risco operacional relativamente contidos no momento: nenhuma entrada consta no catálogo CISA KEV de exploração ativa, taxa que fica abaixo da média geral do catálogo, e não há registros de código de prova de conceito (PoC) publicamente disponível. A falha mais recorrente é do tipo CWE-78 (OS Command Injection), categoria que historicamente representa risco elevado em ambientes de produção por permitir execução arbitrária de comandos no sistema operacional. A CVE de maior atenção no momento é CVE-2020-5633, com score EPSS de 0,0318, indicando probabilidade de exploração ainda baixa, mas que merece monitoramento contínuo dado o tipo de impacto associado a essa classe de vulnerabilidade. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente, embora o volume acumulado de falhas críticas justifique revisão periódica do inventário de ativos NEC expostos.

CVE-2018-0639Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date paEPSS 1.4%CVE-2018-0637Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameteEPSS 1.4%CVE-2018-0628Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request anEPSS 1.4%CVE-2018-0630Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.EPSS 1.4%CVE-2018-0638Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameteEPSS 1.4%CVE-2022-34822CRITICALPath traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SinEPSS 1.4%CVE-2021-20711Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.EPSS 1.4%CVE-2022-34823CRITICALBuffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SiEPSS 1.2%CVE-2021-20708NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware VEPSS 1.2%CVE-2022-34825CRITICALUncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0EPSS 1.2%CVE-2020-5686Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an EPSS 1.2%CVE-2022-34824CRITICALWeak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLEPSS 1.1%CVE-2021-20706Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earEPSS 1.1%CVE-2021-20705Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earEPSS 1.1%CVE-2024-11013HIGHCommand Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to VEPSS 1.1%CVE-2021-20620Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via EPSS 1.0%CVE-2021-20622Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allowsEPSS 1.0%CVE-2020-5635Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specEPSS 1.0%CVE-2020-5524Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 anEPSS 1.0%CVE-2021-20707Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for WindowsEPSS 1.0%