imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2015-6329
Medium 6.5

SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut64074.

cisco prime_collaboration_provisioning
0.02EPSS
CVE-2015-6299
Medium 6.5

SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.

cisco unity_connection
0.02EPSS
CVE-2013-1211
Medium 5.0

Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM access via (1) spoofed STUN packets or (2) a crafted VMware E…

cisco nx-os
0.02EPSS
CVE-2015-6266
Medium 5.0

The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.

cisco identity_services_engine_software
0.02EPSS
CVE-2002-1768
Medium 5.0

Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985.

cisco ios
0.02EPSS
CVE-2002-2052
Medium 5.0

Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the rou…

cisco ios
0.02EPSS
CVE-2002-2053
Medium 5.0

The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, w…

cisco ios
0.02EPSS
CVE-2018-0209
High 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial…

cisco small_business_500_series_stackable_managed_switches_firmware
0.02EPSS
CVE-2015-6308
Medium 4.0

Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.

cisco nx-os
0.02EPSS
CVE-2015-6300
Medium 4.0

Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.

cisco secure_access_control_server
0.02EPSS
CVE-2015-4269
Medium 4.0

The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.

cisco unified_communications_manager
0.02EPSS
CVE-2005-0601
High 7.5

Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.

cisco application_and_content_networking_software
0.02EPSS
CVE-2018-15425
Medium 4.7

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web se…

cisco identity_services_engine
0.02EPSS
CVE-2018-0203
Medium 5.3

A vulnerability in the SMTP relay of Cisco Unity Connection could allow an unauthenticated, remote attacker to send unsolicited email messages, aka a Mail Relay Vulnerability. The vulnerability is due to improper handling of domain information in the affected …

cisco unity_connection
0.02EPSS
CVE-2018-0137
High 8.6

A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate limiting protection for TCP l…

cisco prime_network
0.02EPSS
CVE-2017-12363
Medium 5.3

A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit th…

cisco webex_meetings_server
0.02EPSS
CVE-2017-12318
High 7.5

A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of service…

cisco rf_gateway_1_firmware
0.02EPSS
CVE-2017-12245
High 8.6

A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Servic…

cisco secure_firewall_management_center
0.02EPSS
CVE-2017-6731
High 7.5

A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the MSDP session to be unexpectedly reset, causing a short denial of service (DoS) condit…

cisco ios_xr
0.02EPSS
CVE-2016-9205
High 7.5

A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSC…

cisco ios_xr
0.02EPSS
CVE-2016-6469
High 7.5

A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting. More Information: CSC…

cisco web_security_appliance
0.02EPSS
CVE-2006-4032
Medium 5.0

Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.

cisco callmanager_express
0.02EPSS
CVE-2019-1686
High 8.6

A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. Th…

cisco ios_xr
0.02EPSS
CVE-2010-4354
Medium 5.0

The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the g…

cisco asa_5500 · cisco pix_500 · cisco vpn_3000_concentrator · cisco vpn_3005_concentrator · and 5 more
0.02EPSS
CVE-2007-5550
Medium 5.0

Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service", aka PSIRT-1255024833. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable i…

cisco ios
0.02EPSS