imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2015-0689
High 7.5

Cisco Cloud Web Security before 3.0.1.7 allows remote attackers to bypass intended filtering protection mechanisms by leveraging improper handling of HTTP methods, aka Bug ID CSCut69743.

cisco cloud_web_security
0.01EPSS
CVE-2013-3438
Medium 5.0

The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and read unspecified web pages via crafted parameters, aka Bug ID CSCuh86385.

cisco unified_meetingplace_web_conferencing
0.01EPSS
CVE-2001-0865
High 7.5

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.

cisco 12000_router
0.01EPSS
CVE-2001-0621
High 7.5

The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.

cisco content_services_switch_11000
0.01EPSS
CVE-2017-6720
Medium 6.5

A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is…

cisco esw2-350g-52_firmware · cisco esw2-350g-52dc_firmware · cisco esw2-550x-48_firmware · cisco esw2-550x-48dc_firmware · and 81 more
0.01EPSS
CVE-2014-2151
Medium 4.0

The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2002-1092
High 7.5

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

cisco vpn_3000_concentrator_series_software
0.01EPSS
CVE-2017-3854
High 8.8

A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC in a meshed topology. The vulnerability is due to insufficient authentication of the parent access point in a …

cisco wireless_lan_controller_firmware · cisco wireless_lan_controller_software
0.01EPSS
CVE-2015-6336
High 7.3

Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.

cisco aironet_access_point_software
0.01EPSS
CVE-1999-1306
High 7.5

Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.

cisco ios
0.01EPSS
CVE-2022-20658
Critical 9.6

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote attacker to elevate their privileges to A…

cisco unified_contact_center_express · cisco unified_contact_center_management_portal
0.01EPSS
CVE-2014-2141
Medium 4.0

The session-termination functionality on Cisco ONS 15454 controller cards with software 9.6 and earlier does not initialize an unspecified pointer, which allows remote authenticated users to cause a denial of service (card reset) via crafted session-close acti…

cisco cisco_ons_15454_system_software · cisco ons_15454
0.01EPSS
CVE-2001-0864
High 7.5

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.

cisco 12000_router
0.01EPSS
CVE-2021-1225
Critical 9.1

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management…

cisco sd-wan_vmanage
0.01EPSS
CVE-2021-34769
High 8.6

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of se…

cisco ios_xe
0.01EPSS
CVE-2021-34768
High 8.6

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of se…

cisco ios_xe
0.01EPSS
CVE-2013-5512
High 7.1

Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.4), 9.…

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2020-3446
Critical 9.8

A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to lo…

cisco csp_5228-w_firmware · cisco csp_5436-w_firmware · cisco encs_5406-w_firmware · cisco encs_5408-w_firmware · and 1 more
0.01EPSS
CVE-2019-16026
Medium 5.9

A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an eNodeB that is connected to an…

cisco staros
0.01EPSS
CVE-2016-1383
High 7.5

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

cisco web_security_appliance_\(wsa\)
0.01EPSS
CVE-2016-1381
High 7.5

Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.

cisco web_security_appliance
0.01EPSS
CVE-2011-3297
High 7.8

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authentication configurations are used, allows remote attackers to cause a denial of service (module crash) by making many…

cisco catalyst_6500 · cisco catalyst_7600 · cisco firewall_services_module_software
0.01EPSS
CVE-2009-4923
High 7.8

Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162.

cisco asa_5580
0.01EPSS
CVE-2009-4920
High 7.8

Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software 8.1(2) allows remote attackers to cause a denial of service (watchdog traceback) via a large amount of small-packet data, aka Bug ID CSCsu11412.

cisco asa_5580
0.01EPSS
CVE-2009-4918
High 7.8

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439.

cisco asa_5580
0.01EPSS