imPC@ndo IT

Cisco vulnerabilities

6642 CVE

CVE-2002-1098
High 7.5

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the co…

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client
0.01EPSS
CVE-2021-1491
Medium 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file system of the device. This vulnerability is due to insufficient file scope…

cisco catalyst_sd-wan_manager
0.01EPSS
CVE-2021-1588
High 8.6

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improp…

cisco nx-os
0.01EPSS
CVE-2017-3795
Medium 5.4

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user. More Information: CSCuz03345. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.

cisco webex_meetings_server
0.01EPSS
CVE-2012-5717
Medium 6.3

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device crash) by establishing multiple sessions, aka Bug ID CSCtc59462.…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_1000v_cloud_firewall · cisco asa_5500
0.01EPSS
CVE-2012-0330
High 7.8

Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.

cisco telepresence_system_software · cisco telepresence_video_communication_server
0.01EPSS
CVE-2011-4486
High 7.8

Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow…

cisco business_edition_3000 · cisco business_edition_3000_software · cisco business_edition_5000 · cisco business_edition_5000_software · and 3 more
0.01EPSS
CVE-2012-0352
High 7.8

Cisco NX-OS 4.2.x before 4.2(1)SV1(5.1) on Nexus 1000v series switches; 4.x and 5.0.x before 5.0(2)N1(1) on Nexus 5000 series switches; and 4.2.x before 4.2.8, 5.0.x before 5.0.5, and 5.1.x before 5.1.1 on Nexus 7000 series switches allows remote attackers to …

cisco nexus_1000v · cisco nexus_5000 · cisco nexus_5010 · cisco nexus_5020 · and 8 more
0.01EPSS
CVE-2019-16023
High 7.5

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due…

cisco ios_xr
0.01EPSS
CVE-2019-16019
High 8.6

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due…

cisco ios_xr
0.01EPSS
CVE-2019-16022
High 8.6

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due…

cisco ios_xr
0.01EPSS
CVE-2019-16020
High 8.6

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due…

cisco ios_xr
0.01EPSS
CVE-2019-15989
High 8.6

A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of …

cisco ios_xr
0.01EPSS
CVE-2017-6668
Medium 4.9

Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc…

cisco unified_communications_domain_manager
0.01EPSS
CVE-2011-4500
High 7.5

The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.

cisco linksys_wrt54gx_router_firmware · linksys wrt54gx
0.01EPSS
CVE-2011-4499
High 7.5

The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port ma…

cisco linksys_wrt54g_router_firmware · cisco linksys_wrt54gs_router_firmware · linksys wrt54g · linksys wrt54gs
0.01EPSS
CVE-2012-0331
High 7.5

Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319.

cisco telepresence_system_software · cisco telepresence_video_communication_server
0.01EPSS
CVE-2021-34704
High 8.6

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerabili…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2021-1573
High 8.6

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerabili…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2021-40118
High 8.6

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerabili…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5512-x_firmware · and 7 more
0.01EPSS
CVE-2020-3391
Medium 6.5

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device.…

cisco digital_network_architecture_center
0.01EPSS
CVE-2009-4455
Medium 6.5

The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restri…

cisco adaptive_security_appliance_5500
0.01EPSS
CVE-2002-0880
Medium 5.0

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", an…

cisco skinny_client_control_protocol_software · cisco voip_phone_cp-7940
0.01EPSS
CVE-2019-15983
Medium 4.9

A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrat…

cisco data_center_network_manager
0.01EPSS
CVE-2019-12706
High 7.5

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability…

cisco email_security_appliance_firmware
0.01EPSS