imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2014-3350
Medium 4.0

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.

cisco cloud_portal
0.02EPSS
CVE-2014-3298
Medium 4.0

Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976.

cisco cloud_portal
0.02EPSS
CVE-2016-6372
High 7.5

A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, …

cisco email_security_appliance · cisco web_security_appliance · cisco web_security_appliance_8.0.5
0.02EPSS
CVE-2005-2279
Medium 5.0

Cisco ONS 15216 Optical Add/Drop Multiplexer (OADM) running firmware 2.2.2 and earlier allows remote attackers to cause a denial of service (management plane session loss) via crafted telnet data.

cisco ons_15216_optical_add_drop_multiplexer_software
0.02EPSS
CVE-2005-0599
Medium 5.0

Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.

cisco application_and_content_networking_software
0.02EPSS
CVE-2005-0600
Medium 5.0

Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.

cisco application_and_content_networking_software · cisco content_delivery_manager · cisco content_distribution_manager_4630 · cisco content_distribution_manager_4650 · and 6 more
0.02EPSS
CVE-2004-0307
Medium 5.0

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.

cisco optical_networking_systems_software
0.02EPSS
CVE-2023-20025
Critical 9.0

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to improper valid…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware
0.02EPSS
CVE-2017-6620
Medium 5.8

A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation of t…

cisco small_business_rv_series_router_firmware
0.02EPSS
CVE-2016-6439
High 7.5

A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Software before 6.0.1 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpectedly restarting. T…

cisco secure_firewall_management_center
0.02EPSS
CVE-2014-8027
Medium 6.5

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Update operations via crafted HTTP requests, aka Bug ID CSCuq79034.

cisco secure_access_control_system
0.02EPSS
CVE-2011-3299
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.4), 8.0 before 8.0(5.25), 8.1 and 8.2 before 8.2(5.11), 8.3 before 8.3…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500 · cisco catalyst_6500 · and 2 more
0.02EPSS
CVE-2011-2564
High 7.8

Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of…

cisco intercompany_media_engine · cisco unified_communications_manager
0.02EPSS
CVE-2011-2563
High 7.8

Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of…

cisco intercompany_media_engine · cisco unified_communications_manager
0.02EPSS
CVE-2020-3498
Medium 6.5

A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending special…

cisco jabber
0.02EPSS
CVE-2016-1338
Medium 6.5

Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026.

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2015-0694
Medium 5.0

Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have bee…

cisco asr_9001 · cisco asr_9006 · cisco asr_9010 · cisco asr_9904 · and 3 more
0.02EPSS
CVE-2015-0667
Medium 5.0

The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855.

cisco content_services_switch_11500_firmware
0.02EPSS
CVE-2009-1560
High 7.8

The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pass_wd.htm and (2) Wsecurity.htm, which allows remote attackers to obtain sensitive information by reading the HT…

cisco wvc54gc
0.02EPSS
CVE-2021-1508
Critical 9.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2021-1505
Critical 9.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2007-4011
High 7.1

Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) …

cisco wireless_lan_controller_software
0.02EPSS
CVE-2001-0622
High 7.5

The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the inter…

cisco content_services_switch_11000
0.02EPSS
CVE-2015-0758
Medium 4.0

The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) i…

cisco unified_meetingplace
0.02EPSS
CVE-2014-2179
Medium 5.0

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.

cisco rv120w · cisco rv120w_firmware · cisco rv180 · cisco rv180_firmware · and 3 more
0.02EPSS