imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2017-6784
Medium 5.3

A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attac…

cisco small_business_rv340_firmware · cisco small_business_rv345_firmware · cisco small_business_rv345p_firmware
0.02EPSS
CVE-2017-6730
Medium 5.3

A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker to retrieve completed reports from an affected system, aka Information Disclosure. This vulnerability affects th…

cisco wide_area_application_services
0.02EPSS
CVE-2013-6691
Medium 6.8

The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2011-2072
High 7.8

Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su4, 8.x before 8.5(1)su2, and 8.6 before 8.6(1) allows remote attackers to cause a denial of service (me…

cisco ios · cisco ios_xe · cisco unified_communications_manager
0.02EPSS
CVE-2011-2549
High 7.8

Unspecified vulnerability in Cisco IOS XR 4.1.x before 4.1.1 on Cisco Aggregation Services Routers (ASR) 9000 series devices allows remote attackers to cause a denial of service (line-card reload) via an IPv4 packet, aka Bug ID CSCtr26695.

cisco asr_9006_router · cisco asr_9010_router · cisco ios_xr
0.02EPSS
CVE-2005-0197
Medium 6.1

Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.

cisco ios
0.02EPSS
CVE-2015-6309
Medium 6.8

Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.

cisco email_security_appliance · cisco email_security_appliance_firmware
0.02EPSS
CVE-2014-3407
Medium 5.0

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-3826
High 7.5

A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1a) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, causing …

cisco netflow_generation_appliance_software
0.02EPSS
CVE-2015-4322
Medium 5.5

Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder…

cisco content_security_management_appliance
0.02EPSS
CVE-2019-1844
Medium 5.3

A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection o…

cisco email_security_appliance
0.02EPSS
CVE-2017-6770
Medium 4.2

Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Adverti…

cisco adaptive_security_appliance_software · cisco ios · cisco ios_xe · cisco nx-os · and 3 more
0.02EPSS
CVE-2015-6355
Medium 5.0

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.

cisco unified_computing_system
0.02EPSS
CVE-2012-1312
High 7.1

The MACE feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (device reload) via crafted transit traffic, aka Bug IDs CSCtq64987 and CSCtu57226.

cisco ios
0.02EPSS
CVE-2000-1056
High 7.5

CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.

cisco secure_access_control_server
0.02EPSS
CVE-2008-2730
Medium 5.0

The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, …

cisco unified_communications_manager
0.02EPSS
CVE-2014-0705
High 7.1

The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Snooping is enabled, allows remote attackers to cause a denial of service (device restart) via a malformed IPv6 ML…

cisco wireless_lan_controller · cisco wireless_lan_controller_software
0.02EPSS
CVE-2011-3294
Medium 4.3

Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP …

cisco telepresence_video_communication_servers · cisco telepresence_video_communication_servers_software
0.02EPSS
CVE-2017-12258
Medium 6.1

A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack. The vulnerability exists because the affected software does not provide sufficient prot…

cisco unified_communications_manager
0.02EPSS
CVE-2010-1575
High 7.5

The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted he…

cisco content_services_switch_11500
0.02EPSS
CVE-2021-34749
Medium 5.8

A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on …

cisco firepower_management_center_virtual_appliance_firmware · cisco ironport_web_security_appliance · cisco secure_firewall_management_center
0.02EPSS
CVE-2015-6413
Medium 4.0

Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2009-2873
High 7.1

Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889.

cisco ios
0.02EPSS
CVE-2008-4963
High 7.1

Unspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, allows remote attackers to cause a denial of service (device reload or hang) via a crafted VTP packet sent to a…

cisco catos · cisco ios
0.02EPSS
CVE-2007-5569
High 7.1

Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSCsh97120.

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco pix_500
0.02EPSS