IT

Cisco vulnerabilities

6642 CVE

CVE-2020-3405
High 7.3

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity…

cisco sd-wan_firmware
0.01EPSS
CVE-2020-3164
Medium 5.3

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause h…

cisco cloud_email_security · cisco content_security_management_appliance · cisco email_security_appliance · cisco web_security_appliance
0.01EPSS
CVE-2018-15456
Medium 4.3

A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration p…

cisco identity_services_engine
0.01EPSS
CVE-2018-15382
High 8.6

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit thi…

cisco hyperflex_hx_data_platform
0.01EPSS
CVE-2018-0195
High 8.8

A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerability is due to insufficient authorization c…

cisco ios_xe
0.01EPSS
CVE-2020-3561
Medium 4.7

A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the af…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2017-6755
Medium 6.1

A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Informatio…

cisco prime_collaboration_provisioning
0.01EPSS
CVE-2017-6733
Medium 6.1

A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected s…

cisco identity_services_engine
0.01EPSS
CVE-2017-6725
Medium 6.1

A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65833 CSCuw…

cisco prime_infrastructure
0.01EPSS
CVE-2017-6724
Medium 6.1

A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65843. Know…

cisco prime_infrastructure
0.01EPSS
CVE-2017-6702
Medium 6.1

A vulnerability in the web framework of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCve15285. Known Affected Rel…

cisco socialminer
0.01EPSS
CVE-2017-6701
Medium 6.1

A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system.…

cisco identity_services_engine
0.01EPSS
CVE-2017-6700
Medium 6.1

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a Document Object Model (DOM) based (environment or client-side)…

cisco prime_infrastructure
0.01EPSS
CVE-2017-6699
Medium 6.1

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of …

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.01EPSS
CVE-2017-6690
Medium 4.9

A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary files on an affected system. More Informat…

cisco asr_5000_software
0.01EPSS
CVE-2016-9202
Medium 6.1

A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affe…

cisco email_security_appliance
0.01EPSS
CVE-2012-4658
Medium 5.0

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.

cisco ios
0.01EPSS
CVE-2009-0624
Medium 6.8

Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to …

cisco ace_4710 · cisco application_control_engine_module
0.01EPSS
CVE-2019-15960
Medium 5.4

A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-le…

cisco webex_meetings
0.01EPSS
CVE-2015-0705
Medium 6.8

Cross-site request forgery (CSRF) vulnerability in the SOAP API endpoints of the web-services directory in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to hijack the authentication of administrators for requests that create administrative accoun…

cisco unified_meetingplace
0.01EPSS
CVE-2019-1827
Medium 6.1

A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the service. The vuln…

cisco rv320_firmware · cisco rv325_firmware
0.01EPSS
CVE-2014-0725
Medium 5.0

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.

cisco unified_communications_manager
0.01EPSS
CVE-2018-0340
Medium 5.4

A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. Th…

cisco unified_communications_manager
0.01EPSS
CVE-2012-1324
High 7.1

Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534.

cisco ios
0.01EPSS
CVE-2007-2041
Medium 4.0

Cisco Wireless LAN Controller (WLC) before 4.0.206.0 saves the WLAN ACL configuration with an invalid checksum, which prevents WLAN ACLs from being loaded at boot time, and might allow remote attackers to bypass intended access restrictions, aka Bug ID CSCse58…

cisco 2100_wireless_lan_controller · cisco 4400_wireless_lan_controller
0.01EPSS