imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2014-3349
Medium 4.0

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to upload arbitrary files via a crafted request, aka Bug ID CSCuh87410.

cisco cloud_portal
0.02EPSS
CVE-2014-2145
Medium 4.0

Directory traversal vulnerability in the messaging API in Cisco Unity Connection allows remote authenticated users to read arbitrary files via vectors related to unenforced access constraints for .wav files and the audio/x-wav MIME type, aka Bug ID CSCun91071.…

cisco unity_connection
0.02EPSS
CVE-2001-0862
High 7.5

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.

cisco 12000_router
0.02EPSS
CVE-2013-5513
High 7.1

Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.3), and 9.1.x before 9.1(1.8), when the DNS ALPI eng…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2005-0943
Medium 5.0

Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client · cisco vpn_3005_concentrator_software · cisco vpn_3015_concentrator · and 4 more
0.02EPSS
CVE-2013-1168
High 7.6

The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack session…

cisco unified_meetingplace
0.02EPSS
CVE-2022-20799
Medium 4.7

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2016-1406
High 8.8

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.02EPSS
CVE-2015-6407
Medium 4.0

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

cisco emergency_responder
0.02EPSS
CVE-2009-1165
High 7.8

Memory leak on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0, 5.1 before 5.1.163.0, and 5.0 and 5.2 before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Mo…

cisco catalyst_3750g · cisco cisco_1500_wireless_lan_controller · cisco cisco_2000_wireless_lan_controller · cisco cisco_2100_wireless_lan_controller · and 3 more
0.02EPSS
CVE-2009-1163
High 7.8

Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets.

cisco physical_access_gateway
0.02EPSS
CVE-2009-0061
High 7.8

Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.…

cisco 4400_wireless_lan_controller · cisco catalyst_3750_series_integrated_wireless_lan_controller · cisco catalyst_6500_series_integrated_wireless_lan_controller · cisco catalyst_7600_series_wireless_lan_controller · and 1 more
0.02EPSS
CVE-2007-0963
High 7.8

Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as …

cisco firewall_services_module
0.02EPSS
CVE-2002-0241
High 7.5

NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.

cisco secure_access_control_server
0.02EPSS
CVE-2020-3500
Medium 6.8

A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An atta…

cisco staros
0.02EPSS
CVE-2016-1364
High 7.5

Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908.

cisco wireless_lan_controller_software
0.02EPSS
CVE-2013-6964
Low 3.5

Cisco WebEx Meeting Center allows remote authenticated users to bypass access control and inject content from a different WebEx site via unspecified vectors, aka Bug ID CSCul36197.

cisco webex_meeting_center
0.02EPSS
CVE-2021-34739
High 8.1

A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface o…

cisco cbs250-16p-2g_firmware · cisco cbs250-16t-2g_firmware · cisco cbs250-24fp-4g_firmware · cisco cbs250-24fp-4x_firmware · and 205 more
0.02EPSS
CVE-2021-1304
High 8.8

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and …

cisco catalyst_sd-wan_manager
0.02EPSS
CVE-2006-2166
Low 2.1

Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any us…

cisco unity_express · cisco unity_express_software
0.02EPSS
CVE-2002-1093
Medium 5.0

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

cisco vpn_3000_concentrator_series_software
0.02EPSS
CVE-2002-1102
Medium 5.0

The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote netw…

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client
0.02EPSS
CVE-2002-1104
Medium 5.0

Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

cisco vpn_client
0.02EPSS
CVE-2010-0585
High 7.8

Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control…

cisco ios
0.02EPSS
CVE-2010-0591
High 7.8

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow…

cisco unified_communications_manager
0.02EPSS