imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2014-2166
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCto70562.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2165
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtq72699.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2164
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCuj94651.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2163
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua64961.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2162
High 7.8

The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCud29566.

cisco telepresence_tc_software · cisco telepresence_te_software
0.01EPSS
CVE-2014-2158
High 7.8

Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45720.

cisco tandberg_2000_mxp · cisco tandberg_550_mxp · cisco tandberg_770_mxp · cisco tandberg_880_mxp · and 9 more
0.01EPSS
CVE-2013-5537
High 7.8

The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows remote attackers to cause a denial of s…

cisco content_security_management_appliance · cisco email_security_appliance_firmware · cisco web_security_appliance
0.01EPSS
CVE-2013-5503
High 7.8

The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.

cisco ios_xr
0.01EPSS
CVE-2013-5480
High 7.8

The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.

cisco ios
0.01EPSS
CVE-2013-3390
High 7.8

Memory leak in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug ID CSCub59158.

cisco prime_central_for_hosted_collaboration_solution_assurance
0.01EPSS
CVE-2013-3389
High 7.8

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port (1) 61615 or (2) 61616, aka Bug ID CSCtz90114.

cisco prime_central_for_hosted_collaboration_solution_assurance
0.01EPSS
CVE-2013-3387
High 7.8

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (disk consumption) via a flood of TCP packets to port 5400, leading to large error-log files, aka Bug ID CSCua4…

cisco prime_central_for_hosted_collaboration_solution_assurance
0.01EPSS
CVE-2013-1243
High 7.8

The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (M…

cisco asa_5500-x_series_ips_ssp_software · cisco asa_5585-x · cisco idsm-2 · cisco intrusion_prevention_system · and 5 more
0.01EPSS
CVE-2013-1236
High 7.8

Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing TCP connections at a high rate, aka Bug IDs CSCuf76076 and CSCuf79763.

cisco telepresence_supervisor_mse_8050 · cisco telepresence_supervisor_mse_8050_software
0.01EPSS
CVE-2013-1220
High 7.8

The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.

cisco unified_customer_voice_portal
0.01EPSS
CVE-2013-1147
High 7.8

The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does not properly validate TCP connection information, which allows remote attackers t…

cisco ios
0.01EPSS
CVE-2013-1146
High 7.8

The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.

cisco ios
0.01EPSS
CVE-2013-1145
High 7.8

Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka…

cisco ios
0.01EPSS
CVE-2013-1133
High 7.8

Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to cause a denial of service (CPU consumption and GUI and voice outages) via malformed packets to unused UDP ports, ak…

cisco unified_communications_manager
0.01EPSS
CVE-2012-0378
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allow remote attackers to cause a denial of service (connection limit exceeded) by triggering a large number of stale connections that result in an incorrect value for a…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software
0.01EPSS
CVE-2015-4314
Medium 4.0

The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug ID CSCuv40422.

cisco telepresence_video_communication_server_software
0.01EPSS
CVE-2015-4295
Medium 4.0

The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID CSCuv21819.

cisco unified_communications_manager
0.01EPSS
CVE-2001-0741
Low 2.1

Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.

cisco hsrp
0.01EPSS
CVE-2013-5505
Medium 4.3

Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30275.

cisco identity_services_engine_software
0.01EPSS
CVE-2013-3448
Medium 4.0

Cisco WebEx Meetings Server does not check whether a user account is active, which allows remote authenticated users to bypass intended access restrictions by performing meeting operations after account deactivation, aka Bug ID CSCuh33315.

cisco webex_meetings_server
0.01EPSS