imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2009-4917
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via a high volume of SIP traffic, aka Bug ID CSCsr65901.

cisco asa_5580
0.01EPSS
CVE-2002-1556
Medium 5.0

Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR).

cisco optical_networking_systems_software
0.01EPSS
CVE-2002-1557
Medium 5.0

Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.

cisco optical_networking_systems_software
0.01EPSS
CVE-2021-1542
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Con…

cisco sf220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · and 5 more
0.01EPSS
CVE-2017-11589
Critical 9.8

On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuvi…

cisco residential_gateway_firmware
0.01EPSS
CVE-2001-0056
High 7.5

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

cisco broadband_operating_system
0.01EPSS
CVE-1999-0415
High 7.5

The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.

cisco cisco_7xx_routers
0.01EPSS
CVE-2022-20685
High 7.5

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modb…

cisco cyber_vision · cisco secure_firewall_threat_defense · cisco unified_threat_defense_snort_intrusion_prevention_system_engine
0.01EPSS
CVE-2021-40112
Critical 10.0

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a de…

cisco catalyst_pon_switch_cgp-ont-1p_firmware · cisco catalyst_pon_switch_cgp-ont-4p_firmware · cisco catalyst_pon_switch_cgp-ont-4pv_firmware · cisco catalyst_pon_switch_cgp-ont-4pvc_firmware · and 1 more
0.01EPSS
CVE-2021-34792
High 8.6

A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vu…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · and 6 more
0.01EPSS
CVE-2021-1402
High 8.6

A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vuln…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2016-9224
Medium 6.5

A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).

cisco jabber_guest
0.01EPSS
CVE-2014-3377
Medium 4.0

snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service (process reload) via a malformed SNMPv2 packet, aka Bug ID CSCun67791.

cisco ios_xr
0.01EPSS
CVE-2021-1241
High 8.6

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.…

cisco catalyst_sd-wan_manager · cisco ios_xe_sd-wan · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · and 1 more
0.01EPSS
CVE-2021-1279
High 8.6

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.…

cisco catalyst_sd-wan_manager · cisco ios_xe_sd-wan · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · and 1 more
0.01EPSS
CVE-2021-1273
High 8.6

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.…

cisco catalyst_sd-wan_manager · cisco ios_xe_sd-wan · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · and 1 more
0.01EPSS
CVE-2017-6624
Medium 5.3

A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component…

cisco ios
0.01EPSS
CVE-2012-2474
Medium 4.0

Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bu…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software
0.01EPSS
CVE-2020-3517
High 8.6

A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack…

cisco firepower_extensible_operating_system · cisco nx-os
0.01EPSS
CVE-2022-20862
Medium 4.3

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary file…

cisco unified_communications_manager
0.01EPSS
CVE-2021-1411
Critical 9.9

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information,…

cisco jabber
0.01EPSS
CVE-2015-6362
Medium 4.0

The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640.

cisco connected_grid_network_management_system
0.01EPSS
CVE-2015-0750
Medium 6.5

The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.

cisco hosted_collaboration_solution
0.01EPSS
CVE-2011-0378
High 8.3

The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.

cisco telepresence_system_1000 · cisco telepresence_system_1100 · cisco telepresence_system_1300_series · cisco telepresence_system_3000 · and 3 more
0.01EPSS
CVE-2016-1366
Medium 6.5

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID …

cisco ios_xr
0.01EPSS