imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2014-3294
Medium 4.0

Cisco WebEx Meeting Server does not properly restrict the content of URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuj8…

cisco webex_meetings_server
0.01EPSS
CVE-2014-0743
Medium 5.0

The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468…

cisco unified_communications_manager
0.01EPSS
CVE-2017-12345
Medium 4.7

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client inter…

cisco data_center_network_manager
0.01EPSS
CVE-2016-6408
High 7.5

Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.

cisco prime_home
0.01EPSS
CVE-2008-3820
Medium 6.8

Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these por…

cisco security_manager
0.01EPSS
CVE-2020-3133
High 7.5

A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper validation of inco…

cisco email_security_appliance
0.01EPSS
CVE-2020-3368
Medium 5.8

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to ins…

cisco asyncos
0.01EPSS
CVE-2013-1157
Medium 4.3

Cross-site scripting (XSS) vulnerability in the IBM Tivoli Monitoring (ITM) Java servlet container in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID …

cisco prime_central_for_hosted_collaboration_solution
0.01EPSS
CVE-2003-1001
Medium 5.0

Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.

cisco catalyst_6500 · cisco catalyst_6500_ws-svc-nam-1 · cisco catalyst_6500_ws-svc-nam-2 · cisco catalyst_6500_ws-x6380-nam · and 5 more
0.01EPSS
CVE-2019-1969
Medium 5.3

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is config…

cisco nx-os
0.01EPSS
CVE-2014-3382
High 7.8

The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.1) allows re…

cisco asa
0.01EPSS
CVE-2021-1229
Medium 5.8

A vulnerability in ICMP Version 6 (ICMPv6) processing in Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a slow system memory leak, which over time could lead to a denial of service (DoS) condition. This vulnerability is due to im…

cisco nx-os
0.01EPSS
CVE-2020-3510
High 8.6

A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vuln…

cisco ios_xe
0.01EPSS
CVE-2020-3571
High 8.6

A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2020-3527
High 8.6

A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by s…

cisco ios_xe
0.01EPSS
CVE-2020-3526
High 8.6

A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An…

cisco ios_xe
0.01EPSS
CVE-2020-3492
High 8.6

A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers and Cisco AireOS Software for Cisco Wireless LAN Controllers (WLC) could allow an unauthenticated, remote attacker t…

cisco ios_xe
0.01EPSS
CVE-2020-3475
Medium 4.3

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, …

cisco ios
0.01EPSS
CVE-2019-15289
High 7.5

Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities ar…

cisco roomos · cisco telepresence_collaboration_endpoint
0.01EPSS
CVE-2020-3351
High 8.6

A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of fields in Cisco SD-WAN peering messages that are encapsulated in …

cisco sd-wan_firmware · cisco vedge_cloud_router · cisco vsmart_controller
0.01EPSS
CVE-2019-15261
High 8.6

A vulnerability in the Point-to-Point Tunneling Protocol (PPTP) VPN packet processing functionality in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (Do…

cisco aironet_1810_firmware · cisco aironet_1830_firmware · cisco aironet_1850_firmware
0.01EPSS
CVE-2018-0438
High 7.8

A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vuln…

cisco umbrella_enterprise_roaming_client
0.01EPSS
CVE-2018-15436
Medium 6.1

A vulnerability in the web-based management interface of Cisco Webex Events Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) …

cisco webex_business_suite_31 · cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online
0.01EPSS
CVE-2014-8033
Medium 5.0

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.

cisco webex_meetings_server
0.01EPSS
CVE-2003-1003
High 7.8

Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

cisco pix_firewall · cisco pix_firewall_software
0.01EPSS