imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2017-12248
Medium 6.1

A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability …

cisco unified_intelligence_center
0.02EPSS
CVE-2019-1773
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite · cisco webex_business_suite_lockdown · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2019-1772
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite · cisco webex_business_suite_lockdown · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2019-1715
Medium 5.3

A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, rem…

cisco adaptive_security_appliance_device_manager · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2017-3793
Medium 4.0

A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 through 9.6) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause Cisco ASA and FTD to drop…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-3813
High 7.8

A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vulnerability is due to …

cisco anyconnect_secure_mobility_client
0.02EPSS
CVE-2014-3336
Medium 6.5

SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016.

cisco unity_connection
0.02EPSS
CVE-2012-4663
High 7.1

The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the F…

cisco 5500_series_adaptive_security_appliance · cisco 7600_router · cisco adaptive_security_appliance_software · cisco catalyst_6500 · and 8 more
0.02EPSS
CVE-2012-4662
High 7.1

The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.13) and the F…

cisco 5500_series_adaptive_security_appliance · cisco 7600_router · cisco adaptive_security_appliance_software · cisco catalyst_6500 · and 8 more
0.02EPSS
CVE-2008-2060
High 7.8

Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intende…

cisco intrusion_prevention_system
0.02EPSS
CVE-2001-0866
High 7.5

Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.

cisco 12000_router
0.02EPSS
CVE-2001-0867
High 7.5

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.

cisco 12000_router
0.02EPSS
CVE-2019-1833
Medium 5.8

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due to imprope…

cisco secure_firewall_management_center
0.02EPSS
CVE-2017-6765
Medium 6.1

A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.1(6.11) and 9.4(1.2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management in…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-6771
High 7.5

A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could expl…

cisco ultra_services_framework
0.02EPSS
CVE-2013-5490
High 7.8

Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCud801…

cisco prime_data_center_network_manager
0.02EPSS
CVE-2007-0198
Medium 5.0

The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart…

cisco ip_contact_center_enterprise · cisco ip_contact_center_hosted · cisco unified_contact_center_enterprise · cisco unified_contact_center_hosted
0.02EPSS
CVE-2020-26065
Medium 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due t…

cisco catalyst_sd-wan_manager
0.02EPSS
CVE-2013-5544
Medium 5.4

The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (device reload) by sending many username-from-cert IKE requests, aka Bug ID CSCua91108.

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2004-1775
Medium 5.0

Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.

cisco catos · cisco ios
0.02EPSS
CVE-2019-1863
High 8.1

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to make unauthorized changes to the system configuration. The vulnerability is due to insufficient auth…

cisco integrated_management_controller_supervisor · cisco unified_computing_system
0.02EPSS
CVE-2017-9476
Medium 6.5

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG16…

cisco dpc3939_firmware · commscope arris_tg1682g_firmware
0.02EPSS
CVE-2013-6709
Medium 5.0

The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this U…

cisco webex_training_center
0.02EPSS
CVE-2008-3814
Medium 5.8

Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system …

cisco unity
0.02EPSS
CVE-2017-12295
Medium 5.3

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vu…

cisco webex_meetings_server
0.02EPSS