imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2017-12215
High 7.1

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email mess…

cisco asyncos
0.02EPSS
CVE-2015-6427
Medium 5.0

Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

cisco firesight_system_software
0.02EPSS
CVE-2015-0669
Medium 6.4

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on…

cisco ios
0.02EPSS
CVE-2012-1340
Medium 5.0

The Fibre Channel over IP (FCIP) implementation in Cisco MDS NX-OS 4.2 and 5.2 on MDS 9000 series switches allows remote attackers to cause a denial of service (module reload) via a crafted FCIP header, aka Bug ID CSCtn93151.

cisco mds_9000_nx-os
0.02EPSS
CVE-2006-3073
Low 2.6

Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web sc…

cisco asa_5500 · cisco vpn_3000_concentrator_series_software
0.02EPSS
CVE-2018-15447
Medium 6.5

A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied inpu…

cisco integrated_management_controller
0.02EPSS
CVE-2014-2155
Medium 5.0

The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon reload) via a malformed DHCPv6 packet, aka Bug ID CSCuo07437.

cisco cns_network_registrar
0.02EPSS
CVE-2018-0118
Medium 6.1

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev…

cisco unified_communications_manager
0.02EPSS
CVE-2016-6437
Medium 5.9

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performa…

cisco wide_area_application_services
0.02EPSS
CVE-2015-4286
Medium 5.0

The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuu41377.

cisco unified_computing_system_central_software
0.02EPSS
CVE-2005-1020
High 7.1

Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phas…

cisco ios
0.02EPSS
CVE-2012-4083
Medium 4.0

Multiple buffer overflows in the administrative web interface in Cisco Unified Computing System (UCS) allow remote authenticated users to cause a denial of service (memory corruption and session termination) via long string values for unspecified parameters, a…

cisco unified_computing_system
0.02EPSS
CVE-2009-2868
High 7.8

Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

cisco ios
0.02EPSS
CVE-2018-0111
Medium 5.3

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vu…

cisco webex_meetings_server
0.02EPSS
CVE-2018-0131
Medium 5.9

A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session. The vulnerabilit…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2014-3381
Medium 5.0

The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which allows remote attackers to bypass malware filtering via a crafted archive, aka Bug ID CSCup07934.

cisco asyncos
0.02EPSS
CVE-2020-3200
High 7.7

A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. The vulnerability is due to an internal state not being represented corre…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2018-0457
Medium 5.5

A vulnerability in the Cisco Webex Player for Webex Recording Format (WRF) files could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by sending a user a link or email attach…

cisco webex_meetings_online
0.02EPSS
CVE-2002-1492
High 7.2

Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.

cisco vpn_5000_client
0.02EPSS
CVE-2019-15287
High 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio…

cisco webex_meetings · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2019-15285
High 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio…

cisco webex_meetings · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2019-15283
High 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio…

cisco webex_meetings · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-0103
High 7.8

A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the user …

cisco webex_business_suite · cisco webex_meetings · cisco webex_meetings_server · cisco webex_network_recording_player
0.02EPSS
CVE-2023-20066
Medium 6.5

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient se…

cisco ios_xe
0.02EPSS
CVE-2021-1495
Medium 5.8

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header param…

cisco ios_xe · cisco secure_firewall_threat_defense · snort snort
0.02EPSS