Vulnerabilities in NEC Corporation

89 results
Vexday analysis

O portfólio de vulnerabilidades da NEC Corporation reúne 87 CVEs catalogadas, com 13 classificadas como críticas, mas apresenta indicadores de risco operacional relativamente contidos no momento: nenhuma entrada consta no catálogo CISA KEV de exploração ativa, taxa que fica abaixo da média geral do catálogo, e não há registros de código de prova de conceito (PoC) publicamente disponível. A falha mais recorrente é do tipo CWE-78 (OS Command Injection), categoria que historicamente representa risco elevado em ambientes de produção por permitir execução arbitrária de comandos no sistema operacional. A CVE de maior atenção no momento é CVE-2020-5633, com score EPSS de 0,0318, indicando probabilidade de exploração ainda baixa, mas que merece monitoramento contínuo dado o tipo de impacto associado a essa classe de vulnerabilidade. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente, embora o volume acumulado de falhas críticas justifique revisão periódica do inventário de ativos NEC expostos.

CVE-2020-5534Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands wEPSS 0.9%CVE-2020-5525Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 anEPSS 0.9%CVE-2021-20712Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware Ver1.1.2 and earlier EPSS 0.8%CVE-2020-5533Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script orEPSS 0.8%CVE-2021-20680Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 aEPSS 0.8%CVE-2021-20710Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script viaEPSS 0.8%CVE-2020-5636Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request EPSS 0.8%CVE-2024-28012CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2023-39548CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.7%CVE-2023-39545CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.7%CVE-2018-16195Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attEPSS 0.7%CVE-2023-3333Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG18EPSS 0.7%CVE-2024-28014CRITICALStack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HEPSS 0.7%CVE-2024-28015CRITICALImproper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WGEPSS 0.7%CVE-2021-20709Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1EPSS 0.7%CVE-2024-28009CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2024-28007CRITICALImproper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WEPSS 0.7%CVE-2021-20621Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and eEPSS 0.6%CVE-2023-39546CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.6%CVE-2023-39547CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleEPSS 0.6%