IT

Cisco vulnerabilities

6642 CVE

CVE-1999-0998
Medium 5.0

Cisco Cache Engine allows an attacker to replace content in the cache.

cisco cache_engine
0.01EPSS
CVE-2021-1460
Medium 5.3

A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, …

cisco cgr1000_firmware · cisco ic3000_industrial_compute_gateway_firmware · cisco ios
0.01EPSS
CVE-2015-6358
Medium 5.9

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these cert…

cisco pvc2300_firmware · cisco rtp300_firmware · cisco rv120w_firmware · cisco rv180_firmware · and 20 more
0.01EPSS
CVE-2006-4983
High 7.5

Cisco NAC allows quarantined devices to communicate over the network with (1) DNS, (2) DHCP, and (3) EAPoUDP, which allows attackers to bypass control methods by tunneling network traffic through one of these protocols.

cisco network_access_control
0.01EPSS
CVE-2014-3307
Medium 6.8

The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513.

cisco universal_small_cell_series_firmware
0.01EPSS
CVE-2021-1577
Critical 9.1

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an aff…

cisco application_policy_infrastructure_controller · cisco cloud_application_policy_infrastructure_controller
0.01EPSS
CVE-2018-0380
Medium 5.5

Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via em…

cisco webex_meetings_online
0.01EPSS
CVE-2017-12364
Medium 6.5

A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-supplied i…

cisco prime_service_catalog
0.01EPSS
CVE-2016-6426
High 7.5

The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page,…

cisco unified_contact_center_express · cisco unified_intelligence_center
0.01EPSS
CVE-2015-4550
Medium 4.3

The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec a…

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2021-1464
Medium 5.0

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the affec…

cisco catalyst_sd-wan_manager
0.01EPSS
CVE-2014-3296
Medium 4.0

The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.

cisco webex_meetings_server
0.01EPSS
CVE-2002-0852
Medium 5.0

Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large …

cisco vpn_client
0.01EPSS
CVE-2023-20026
Medium 6.5

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due t…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware
0.01EPSS
CVE-2021-1305
High 8.8

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and …

cisco ios_xe_sd-wan · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.01EPSS
CVE-2017-6754
Medium 6.5

A vulnerability in the web-based management interface of the Cisco Smart Net Total Care (SNTC) Software Collector Appliance 3.11 could allow an authenticated, remote attacker to perform a read-only, blind SQL injection attack, which could allow the attacker to…

cisco smart_net_total_care_collector_appliance
0.01EPSS
CVE-2009-5039
Medium 5.0

Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by Inter…

cisco ios
0.01EPSS
CVE-2017-6789
Medium 6.1

A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting (XSS)…

cisco unified_intelligence_center
0.01EPSS
CVE-2022-20751
High 8.6

A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause unlimited memory consumption, which could lead to a denial of service (DoS) condition on an aff…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2022-20746
High 8.6

A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper handling of TCP flows. An atta…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2022-20715
High 8.6

A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affec…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2022-20682
High 8.6

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) …

cisco ios_xe
0.01EPSS
CVE-2016-1358
Medium 6.4

Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Ex…

cisco prime_infrastructure
0.01EPSS
CVE-2016-1334
Medium 5.3

Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.

cisco small_business_wireless_access_points_firmware
0.01EPSS
CVE-2017-6709
Critical 9.8

A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. T…

cisco ultra_services_framework
0.01EPSS