imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2013-1190
Medium 5.0

The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets,…

cisco unified_computing_system
0.01EPSS
CVE-2012-3913
Medium 5.0

The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019.

cisco vc240_network_bullet_camera · cisco video_surveillance_vc220_network_dome_camera
0.01EPSS
CVE-2013-1138
Medium 5.0

The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (connections-table memory consumption) via crafted packets, aka Bug ID CSCue46386.

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.01EPSS
CVE-2019-12710
Medium 4.9

A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by ex…

cisco unified_communications_manager
0.01EPSS
CVE-2019-1977
Medium 6.8

A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device…

cisco nx-os
0.01EPSS
CVE-2018-0207
Low 3.3

A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improp…

cisco secure_access_control_server_solution_engine
0.01EPSS
CVE-2021-1446
High 8.6

A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a log…

cisco ios_xe
0.01EPSS
CVE-2021-1437
High 7.5

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial F…

cisco aironet_access_point_software · cisco catalyst_9800_firmware · cisco wireless_lan_controller_software
0.01EPSS
CVE-2020-3444
High 7.5

A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker …

cisco ios_xe
0.01EPSS
CVE-2021-1373
High 8.6

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause…

cisco ios_xe
0.01EPSS
CVE-2019-12701
Medium 5.8

A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists be…

cisco secure_firewall_management_center · cisco vdb_fingerprint_database
0.01EPSS
CVE-2019-1970
Medium 5.8

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected s…

cisco secure_firewall_management_center · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2019-1909
Medium 6.8

A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorr…

cisco ios_xr
0.01EPSS
CVE-2016-1290
High 8.1

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a …

cisco evolved_programmable_network_manager · cisco prime_infrastructure · sun opensolaris
0.01EPSS
CVE-2007-0964
Medium 5.4

Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.

cisco firewall_services_module
0.01EPSS
CVE-2019-1953
Medium 6.5

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password when a user is forced t…

cisco enterprise_network_function_virtualization_infrastructure
0.01EPSS
CVE-2016-1380
High 7.5

Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.

cisco web_security_appliance
0.01EPSS
CVE-2018-0474
High 8.8

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in conf…

cisco unified_communications_manager
0.01EPSS
CVE-2020-3142
High 7.5

A vulnerability in Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites could allow an unauthenticated, remote attendee to join a password-protected meeting without providing the meeting password. The connection attempt must initiate from a W…

cisco webex_meetings_online
0.01EPSS
CVE-2017-3844
Medium 4.3

A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. Affected Products: Cisco Prime Collaboration Assurance softwa…

cisco prime_collaboration_assurance
0.01EPSS
CVE-2017-3843
Medium 4.3

A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. More Information: CSCvc99446. Known Affected Releases: 11.5(0).

cisco prime_collaboration_assurance
0.01EPSS
CVE-2007-3776
Medium 5.0

Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj…

cisco unified_communications_manager · cisco unified_presence_server
0.01EPSS
CVE-1999-0158
Medium 5.0

Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.

cisco pix_firewall_software
0.01EPSS
CVE-2019-12693
Medium 4.9

A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.01EPSS
CVE-2014-3324
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup9006…

cisco telepresence_server_software
0.01EPSS