imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2011-1623
High 10.0

Cisco Media Processing Software before 1.2 on Media Experience Engine (MXE) 5600 devices has a default root password, which makes it easier for context-dependent attackers to obtain access via (1) the local console, (2) an SSH session, or (3) a TELNET session,…

cisco media_experience_engine_5600 · cisco media_processing_software
0.02EPSS
CVE-2019-1984
Medium 6.5

A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. T…

cisco enterprise_network_function_virtualization_infrastructure_sofware
0.02EPSS
CVE-2013-5488
Medium 5.0

Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to c…

cisco prime_lan_management_solution · cisco security_manager · cisco unified_operations_manager · cisco unified_service_monitor
0.02EPSS
CVE-2007-5582
Medium 4.3

Cross-site scripting (XSS) vulnerability in the login page in Cisco CiscoWorks Server (CS), possibly 2.6 and earlier, when using CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

cisco ciscoworks_server
0.02EPSS
CVE-2007-4284
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified MeetingPlace Web Conferencing (MP) 5.3.235.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) Success Template (STPL) and (2) Failure Template (FTPL) par…

cisco meetingplace_web_confrencing
0.02EPSS
CVE-2020-26075
High 8.8

A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insufficient input validation of REST API request…

cisco iot_field_network_director
0.02EPSS
CVE-2020-3235
High 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerab…

cisco ios · cisco ios_xe · oracle goldengate_management_pack
0.02EPSS
CVE-2019-12704
Medium 6.5

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper inpu…

cisco spa112_firmware · cisco spa122_firmware
0.02EPSS
CVE-2017-12267
Medium 5.3

A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an ICA application optimization-related process to restart, resulti…

cisco virtual_wide_area_application_services · cisco wide_area_application_services
0.02EPSS
CVE-2016-1484
High 7.5

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.

cisco webex_meetings_server
0.02EPSS
CVE-2020-3181
Medium 6.5

A vulnerability in the malware detection functionality in Cisco Advanced Malware Protection (AMP) in Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated remote attacker to exhaust resources on an affected device. Th…

cisco email_security_appliance
0.02EPSS
CVE-2020-3165
High 8.2

A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. Th…

cisco nx-os
0.02EPSS
CVE-2019-1853
Medium 4.8

A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs …

cisco anyconnect_secure_mobility_client
0.02EPSS
CVE-2018-0284
Medium 6.5

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local sta…

cisco meraki_mr_24_firmware · cisco meraki_mr_25_firmware · cisco meraki_ms_10_firmware · cisco meraki_ms_9_firmware · and 3 more
0.02EPSS
CVE-2018-0140
Medium 6.5

A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The…

cisco content_security_management_appliance · cisco email_security_appliance_firmware
0.02EPSS
CVE-2013-3460
High 7.8

Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a high rate of UDP packets, aka Bug ID CSCub…

cisco unified_communications_manager
0.02EPSS
CVE-2019-12632
High 7.5

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly val…

cisco finesse
0.02EPSS
CVE-2015-0762
Medium 4.3

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft Outlook allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu51400.

cisco unified_meetingplace
0.02EPSS
CVE-2015-0733
Medium 4.3

CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks or cross-site scripting (XSS) att…

cisco headend_digital_broadband_delivery_system
0.02EPSS
CVE-2015-0752
Medium 4.3

Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

cisco telepresence_video_communication_server
0.02EPSS
CVE-2014-3366
Medium 6.5

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3275
Medium 6.5

SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337.

cisco identity_services_engine_software
0.02EPSS
CVE-2017-3836
Medium 4.3

A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12…

cisco unified_communications_manager
0.02EPSS
CVE-2012-4621
High 7.8

The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049.

cisco ios
0.02EPSS
CVE-2011-2059
Medium 5.0

The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (…

cisco ios
0.02EPSS