imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2015-0688
High 7.1

Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.

cisco ios_xe
0.02EPSS
CVE-2015-0616
High 7.1

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump an…

cisco unity_connection
0.02EPSS
CVE-2015-0615
High 7.1

The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumpt…

cisco unity_connection
0.02EPSS
CVE-2015-0614
High 7.1

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial …

cisco unity_connection
0.02EPSS
CVE-2015-0613
High 7.1

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial …

cisco unity_connection
0.02EPSS
CVE-2015-0612
High 7.1

The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU6, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (SIP outage) …

cisco unity_connection · cisco unity_connection_8.5 · cisco unity_connection_8.6
0.02EPSS
CVE-2014-3392
High 8.3

The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.8), and 9.3 before 9.3(1.1) allows remote attackers to obta…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2014-3395
Medium 5.0

Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.

cisco webex_meetings_server
0.02EPSS
CVE-1999-0161
High 7.5

In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.

cisco ios
0.02EPSS
CVE-2020-3162
High 7.5

A vulnerability in the Constrained Application Protocol (CoAP) implementation of Cisco IoT Field Network Director could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to ins…

cisco iot_field_network_director
0.02EPSS
CVE-2019-1720
Medium 6.8

A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an …

cisco telepresence_video_communication_server
0.02EPSS
CVE-2013-1246
Medium 6.8

Cisco TelePresence System Software does not properly handle inactive t-shell sessions, which allows remote authenticated users to cause a denial of service (memory consumption and service outage) by establishing multiple SSH connections, aka Bug ID CSCug77610.…

cisco telepresence_system_software
0.02EPSS
CVE-2016-1388
Critical 9.8

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow remote attackers to execute arbitrary OS commands v…

cisco network_analysis_module · cisco prime_network_analysis_module_software · cisco prime_virtual_network_analysis_module_software
0.02EPSS
CVE-2013-6696
High 7.1

Cisco Adaptive Security Appliance (ASA) Software does not properly handle errors during the processing of DNS responses, which allows remote attackers to cause a denial of service (device reload) via a malformed response, aka Bug ID CSCuj28861.

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2022-20713
Medium 4.3

A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2018-0160
Medium 6.3

A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of memory resources, ref…

cisco ios_xe
0.02EPSS
CVE-2017-6656
Medium 5.9

A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process unexpectedly restarting. All active pho…

cisco ip_phone_8800_series
0.02EPSS
CVE-2014-2107
High 7.1

Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of service (route switch processor outage) via crafted IP packets, aka Bug ID CSCug84789.…

cisco ios
0.02EPSS
CVE-2014-0718
High 7.1

The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via fragmented packets, aka Bug ID CSCui91266.

cisco ips_sensor_software
0.02EPSS
CVE-2013-5549
High 7.1

Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, a…

cisco ios_xr
0.02EPSS
CVE-2007-2032
High 7.5

Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID…

cisco wireless_control_system
0.02EPSS
CVE-2021-1555
Medium 4.7

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These …

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · and 2 more
0.02EPSS
CVE-2021-1553
Medium 4.7

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These …

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · and 2 more
0.02EPSS
CVE-2021-1552
Medium 4.7

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These …

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · and 2 more
0.02EPSS
CVE-2021-1551
Medium 4.7

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These …

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · and 2 more
0.02EPSS