imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2011-4006
High 7.8

The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software
0.01EPSS
CVE-2022-20622
High 8.6

A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) conditi…

cisco aironet_access_point_software
0.01EPSS
CVE-2014-8036
Medium 5.0

The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invite list via a crafted URL, aka Bug ID CSCuj40254.

cisco webex_meetings_server
0.01EPSS
CVE-2013-3380
Medium 4.0

The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID …

cisco secure_access_control_server_solution_engine
0.01EPSS
CVE-2015-4190
Medium 4.3

Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.

cisco prime_service_catalog
0.01EPSS
CVE-2015-0686
Medium 6.3

The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq92240.

cisco nx-os
0.01EPSS
CVE-2013-1203
Medium 5.4

Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear to have been forwarded by a Cisco Adaptive Security Appliances (ASA) device, aka Bug ID CSCue88386.

cisco asa_cx_context-aware_security_software
0.01EPSS
CVE-2013-1184
High 7.8

The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS) 1.x before 1.2(1b) allows remote attackers to cause a denial of service (service outage) via a malformed request, aka Bug ID CSCtg48206.

cisco unified_computing_system_6120xp_fabric_interconnect · cisco unified_computing_system_6140xp_fabric_interconnect · cisco unified_computing_system_6248up_fabric_interconnect · cisco unified_computing_system_6296up_fabric_interconnect · and 2 more
0.01EPSS
CVE-2012-5419
High 7.8

Cisco Adaptive Security Appliance (ASA) software 8.7.1 and 8.7.1.1 for the Cisco ASA 1000V Cloud Firewall allows remote attackers to cause a denial of service (device reload) via a malformed H.225 H.323 IPv4 packet, aka Bug IDs CSCuc42812 and CSCuc88741.

cisco adaptive_security_appliance_software · cisco asa_1000v_cloud_firewall
0.01EPSS
CVE-2011-4023
High 7.8

Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682.

cisco nexus_2148t_fex_switch · cisco nexus_2224tp_fex_switch · cisco nexus_2232pp_fex_switch · cisco nexus_2232tm_fex_switch · and 8 more
0.01EPSS
CVE-2006-3732
Medium 5.0

Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information.

cisco cs-mars
0.01EPSS
CVE-2020-3564
Medium 5.3

A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerability is due to ineffective…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2020-3186
Medium 5.3

A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due…

cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · and 9 more
0.01EPSS
CVE-2015-0673
Medium 4.0

Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.

cisco mobility_services_engine
0.01EPSS
CVE-2014-2102
Medium 4.0

Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575.

cisco unified_contact_center_express_editor_software
0.01EPSS
CVE-2021-34697
Medium 5.8

A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is…

cisco ios_xe
0.01EPSS
CVE-2021-1624
High 8.6

A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denia…

cisco ios_xe
0.01EPSS
CVE-2021-1615
High 8.6

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vu…

cisco embedded_wireless_controller
0.01EPSS
CVE-2021-1611
High 8.6

A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9800 Family Wireless Controller, Embedded Wireless Controller, and Embedded Wireless on Catalyst 9000 Series Switches could allow…

cisco ios_xe
0.01EPSS
CVE-2021-34737
Medium 5.8

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because …

cisco ios_xr
0.01EPSS
CVE-2021-1523
High 8.6

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control plane traffic to the dev…

cisco nx-os
0.01EPSS
CVE-2014-3388
High 7.8

The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 before 9.2(2) allows remote attackers to cause a denial of service (device reload) via crafted DNS packets, aka Bug ID CSCuo68327.

cisco asa
0.01EPSS
CVE-2014-3387
High 7.8

The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.3) allows rem…

cisco asa
0.01EPSS
CVE-2014-2175
High 7.8

Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of service (memory consumption) via crafted H.225 packets, aka Bug ID CSCtq78849.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2167
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua86589.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS