imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2021-1513
High 7.5

A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packe…

cisco catalyst_sd-wan_manager · cisco sd-wan_vbond_orchestrator · cisco vedge-100b_firmware · cisco vedge_1000_firmware · and 8 more
0.02EPSS
CVE-2019-1629
Medium 5.3

A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delet…

cisco integrated_management_controller · cisco unified_computing_system
0.02EPSS
CVE-2019-1872
Medium 5.3

A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper res…

cisco telepresence_video_communication_server
0.02EPSS
CVE-2018-0437
High 7.8

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vuln…

cisco umbrella_enterprise_roaming_client · cisco umbrella_roaming_module
0.02EPSS
CVE-2019-12633
High 7.5

A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper v…

cisco unified_contact_center_express
0.02EPSS
CVE-2021-34701
Medium 4.3

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unifie…

cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service · cisco unity_connection
0.02EPSS
CVE-2019-16027
Medium 6.5

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition…

cisco ios_xr
0.02EPSS
CVE-2019-12714
Medium 6.5

A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected sof…

cisco ic3000_industrial_compute_gateway_firmware
0.02EPSS
CVE-2019-1884
High 7.7

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff…

cisco asyncos · cisco web_security_appliance
0.02EPSS
CVE-2015-6384
Medium 4.3

The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.

cisco webex_meetings
0.02EPSS
CVE-2014-0655
Medium 4.3

The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to change the user-cache contents via a replay attack involving crafted RADIUS Change of Authorization (CoA) messages, aka Bug ID CSCuj45332.…

cisco adaptive_security_appliance
0.02EPSS
CVE-2020-3407
High 8.6

A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL that is tied…

cisco ios_xe
0.02EPSS
CVE-2018-15389
Critical 9.8

A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. Th…

cisco prime_collaboration
0.02EPSS
CVE-2020-3359
High 8.6

A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper …

cisco ios_xe
0.02EPSS
CVE-2020-3221
High 8.6

A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …

cisco ios_xe
0.02EPSS
CVE-2020-3272
High 7.5

A vulnerability in the DHCP server of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of incoming DHCP t…

cisco prime_network_registrar
0.02EPSS
CVE-2017-9486
High 7.5

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to compute password-of-the-day values via unspecified vectors.

cisco dpc3939_firmware
0.02EPSS
CVE-2017-9484
High 7.5

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover a CM MAC address by sniffing Wi-Fi traffic…

cisco dpc3939_firmware
0.02EPSS
CVE-2017-9478
High 7.5

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices sets the CM MAC address to a value with a two-byte offset from the MTA/VoIP MA…

cisco dpc3939_firmware
0.02EPSS
CVE-2015-6395
Medium 6.5

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

cisco prime_service_catalog
0.02EPSS
CVE-2015-6379
Medium 6.8

The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2012-0360
Medium 5.0

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

cisco ios
0.02EPSS
CVE-2020-3132
Medium 5.9

A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of service (DoS) condition on an affected device. The vulnerabi…

cisco cloud_email_security · cisco email_security_appliance
0.02EPSS
CVE-2019-1926
High 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2017-3840
Medium 6.1

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Re…

cisco secure_access_control_system
0.02EPSS