access:pre-auth 类型相关 26535 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2017-3885 | Cisco Firepower System Software 安全漏洞 — Cisco Firepower Detection Engine | 5.9 | - | 2017-04-07 |
| CVE-2017-3887 | Cisco Firepower System Software 安全漏洞 — Cisco Firepower Detection Engine | 7.5 | - | 2017-04-07 |
| CVE-2017-3889 | Cisco Registered Envelope Service 输入验证漏洞 — Cisco Registered Envelope Service | 6.1 | - | 2017-04-07 |
| CVE-2017-6599 | Cisco IOS XR Software 安全漏洞 — Cisco IOS XR Software | 5.3 | - | 2017-04-07 |
| CVE-2017-6603 | Cisco ASR 903和ASR 920 Series设备资源管理错误漏洞 — Cisco ASR 903 and ASR 920 Series Devices | 6.5 | - | 2017-04-07 |
| CVE-2017-6604 | 多款Cisco产品Integrated Management Controller Software 安全漏洞 — Cisco Integrated Management Controller | 6.1 | - | 2017-04-07 |
| CVE-2017-6606 | Cisco IOS XE Software 命令注入漏洞 — Cisco IOS XE | 6.4 | - | 2017-04-07 |
| CVE-2016-9194 | Cisco Wireless LAN Controller 资源管理错误漏洞 — Cisco Wireless LAN Controller CWE-399 | 6.5 | - | 2017-04-06 |
| CVE-2016-9219 | Cisco Wireless LAN Controller 输入验证错误漏洞 — Cisco Wireless LAN Controller CWE-20 | 7.5 | - | 2017-04-06 |
| CVE-2017-3832 | Cisco Wireless LAN Controller 权限许可和访问控制问题漏洞 — Cisco Wireless LAN Controller CWE-264 | 7.5 | - | 2017-04-06 |
| CVE-2017-3834 | Cisco Aironet 1830 Series和Cisco Aironet 1850 Series Access Points Mobility Express Software 信任管理问题漏洞 — Cisco Aironet 1830 Series and 1850 Series Access Points CWE-255 | 9.8 | - | 2017-04-06 |
| CVE-2017-7237 | Spiceworks Inventory Spiceworks TFTP Server 安全漏洞 — n/a | 9.1 | - | 2017-04-06 |
| CVE-2017-0305 | F5 SSL Intercept iApp 安全漏洞 — SSL Intercept iApp version | 9.8 | - | 2017-04-06 |
| CVE-2017-7450 | AIRTAME HDMI dongle 安全漏洞 — n/a | 9.8 | - | 2017-04-05 |
| CVE-2014-9136 | Huawei FusionManager 跨站请求伪造漏洞 — FusionManager FusionManager All V100R002C03 versions, All V100R003C00 versions, | 8.8 | - | 2017-04-02 |
| CVE-2014-9137 | 多款华为防火墙USG系列产品跨站请求伪造漏洞 — USG9500,USG2100,USG2200,USG5100,USG5500, USG9500 V200R001C01SPC800 and earlier versions, All V300R001C00 versions,USG2100 V300R001C00SPC900 and earlier versions,USG2200 V300R001C00SPC900,USG5100 V300R001C00SPC900, | 8.8 | - | 2017-04-02 |
| CVE-2016-8795 | 多款Huawei CloudEngine产品整数溢出漏洞 — CloudEngine 5800, CloudEngine 6800, CloudEngine 7800, CloudEngine 8800,CloudEngine 12800, Secospace USG6600 CloudEngine 12800 V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00,CloudEngine 5800 V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, CloudEngine 6800 V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00,CloudEngine 7800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00, CloudEngine 8800 V100R006C00, Secospace USG6600 V500R001C00 | 7.5 | - | 2017-04-02 |
| CVE-2016-8796 | 多款Huawei设备拒绝服务漏洞 — USG9520,USG9560,USG9580, USG9520 V300R001C01,USG9560 V300R001C01,USG9580 V300R001C01 | 7.5 | - | 2017-04-02 |
| CVE-2017-7392 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7394 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7396 | TigerVNC 安全漏洞 — n/a | 7.5 | - | 2017-04-01 |
| CVE-2017-7285 | MikroTik RouterBoard 安全漏洞 — n/a | 7.5 | - | 2017-03-29 |
| CVE-2016-9463 | Nextcloud Server和ownCloud Server 安全漏洞 — Nextcloud Server & ownCloud Server Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 CWE-303 | 9.8 | - | 2017-03-28 |
| CVE-2016-9469 | GitLab 安全漏洞 — GitLab Community Edition & GitLab Enterprise Edition 8.13.0, 8.13.0-ee, 8.13.1, 8.13.1-ee, 8.13.2, 8.13.2-ee, 8.13.3, 8.13.3-ee, 8.13.4, 8.13.4-ee, 8.13.5, 8.13.5-ee, 8.13.6, 8.13.6-ee, 8.13.7, 8.14.0, 8.14.0-ee, 8.14.1 CWE-749 | 8.2 | - | 2017-03-28 |
| CVE-2017-5237 | Eview EV-07S GPS Tracker 安全漏洞 — EV-07S GPS Tracker | 9.1 | - | 2017-03-27 |
| CVE-2017-2643 | Moodle 安全漏洞 — Moodle 3.2.x | 5.3 | - | 2017-03-26 |
| CVE-2016-7797 | Pacemaker 安全漏洞 — n/a | 5.9 | - | 2017-03-24 |
| CVE-2017-7240 | Miele Professional PG 8528 PST10 路径遍历漏洞 — n/a | 7.5 | - | 2017-03-24 |
| CVE-2017-6517 | Microsoft Skype 安全漏洞 — n/a | 8.8 | - | 2017-03-23 |
| CVE-2016-7468 | F5 BIG-IP 安全漏洞 — F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, PEM, PSM, | 7.5 | - | 2017-03-23 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 26535 条 CVE 漏洞。