imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2016-6465
Medium 4.3

A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affected de…

cisco email_security_appliance
0.02EPSS
CVE-2020-3408
High 8.6

A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability occurs because t…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2020-3226
High 8.6

A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vu…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2017-6711
Critical 9.1

A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulnerability is due to an insecure default configuration of the A…

cisco ultra_services_framework
0.02EPSS
CVE-2016-6460
High 7.5

A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass FTP malware detection rules and download malware over an FTP c…

cisco firesight_system_software
0.02EPSS
CVE-2015-0617
Medium 5.0

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outage) via malformed SNMP packets, aka Bug ID CSCur13393.

cisco asr_5000_series_software
0.02EPSS
CVE-2014-8004
Medium 5.0

Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

cisco ios_xr
0.02EPSS
CVE-2013-3435
Medium 5.0

The Cisco Unified IP Conference Station 7937G allows remote attackers to cause a denial of service (networking outage) via a flood of TCP packets, aka Bug ID CSCuh42052.

cisco unified_ip_conference_station_7937g · cisco unified_ip_conference_station_7937g_firmware
0.02EPSS
CVE-2013-1154
Medium 5.0

The Cisco Small Business 200 Series Smart Switch 1.2.7.76 and earlier, Small Business 300 Series Managed Switch 1.2.7.76 and earlier, and Small Business 500 Series Stackable Managed Switch 1.2.7.76 and earlier allow remote attackers to cause a denial of servic…

cisco 200_series_smart_switches · cisco 200_series_smart_switches_software · cisco 300_series_managed_switches · cisco 500_series_stackable_managed_switches
0.02EPSS
CVE-2013-1112
Medium 5.0

Cisco Carrier Routing System (CRS) allows remote attackers to cause a denial of service (packet loss) via short malformed packets that trigger inefficient processing, aka Bug ID CSCud79136.

cisco carrier_routing_system
0.02EPSS
CVE-2011-3283
Medium 5.0

Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug ID CSCts14887.

cisco carrier_routing_system
0.02EPSS
CVE-2018-0292
High 8.8

A vulnerability in the Internet Group Management Protocol (IGMP) Snooping feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an …

cisco nx-os
0.02EPSS
CVE-2010-2830
High 7.1

The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, when PIM is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed IGMP packet, aka Bug ID CSCte14603.

cisco ios · cisco ios_xe
0.02EPSS
CVE-2021-34783
High 8.6

A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a …

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · and 6 more
0.02EPSS
CVE-2017-3839
Medium 4.3

An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information:…

cisco secure_access_control_system
0.02EPSS
CVE-2014-3262
Medium 4.3

The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via ma…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2005-0612
High 7.5

Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.

cisco ipvc-3510-mcu · cisco ipvc-3520-gw-2b · cisco ipvc-3520-gw-2b2v · cisco ipvc-3520-gw-2v · and 3 more
0.02EPSS
CVE-2015-0593
High 7.1

The Zone-Based Firewall implementation in Cisco IOS 12.4(122)T and earlier does not properly manage session-object structures, which allows remote attackers to cause a denial of service (device reload) via crafted network traffic, aka Bug ID CSCul65003.

cisco ios
0.02EPSS
CVE-2012-4622
High 7.1

Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E card is installed, allows remote attackers to cause a denial of service (card reload) via malformed packets that trigger uncorrected ECC error messages, aka Bug…

cisco ios_xe
0.02EPSS
CVE-2012-3950
High 7.1

The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, ak…

cisco ios
0.02EPSS
CVE-2008-3815
Medium 4.3

Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Wi…

cisco asa_5500 · cisco pix
0.02EPSS
CVE-2020-3441
Medium 5.3

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant inf…

cisco webex_meetings · cisco webex_meetings_server
0.02EPSS
CVE-2015-6261
Medium 4.0

Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, a…

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2015-4270
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.5 and 6.0.0 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuv22557, CSCuv22583, CSCuv22632, CSCuv22641, CSCuv22650, CS…

cisco firesight_system_software
0.02EPSS
CVE-2015-4268
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST reques…

cisco identity_services_engine_software
0.02EPSS