IT

Cisco vulnerabilities

6647 CVE

CVE-2012-3915
Medium 5.0

The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602.

cisco ios
0.01EPSS
CVE-2012-3901
Medium 5.0

The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.

cisco intrusion_prevention_system · cisco ips_4240 · cisco ips_4250_sx · cisco ips_4255 · and 2 more
0.01EPSS
CVE-2012-1339
Medium 5.0

The Fabric Interconnect component in Cisco Unified Computing System (UCS) 2.0 allows remote attackers to cause a denial of service (process crash) via an attempted SSH session, aka Bug ID CSCtt94543.

cisco unified_computing_system_infrastructure_and_unified_computing_system_software
0.01EPSS
CVE-2012-0361
Medium 5.0

The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook…

cisco ip_communicator
0.01EPSS
CVE-2011-4015
Medium 5.0

Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts48300.

cisco ios
0.01EPSS
CVE-2015-6368
Medium 5.0

Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.

cisco firepower_extensible_operating_system
0.01EPSS
CVE-2012-4074
Medium 5.8

The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream by levera…

cisco unified_computing_system
0.01EPSS
CVE-2021-1509
High 7.5

Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec…

cisco vedge_1000_firmware · cisco vedge_100_firmware · cisco vedge_100b_firmware · cisco vedge_100m_firmware · and 4 more
0.01EPSS
CVE-2020-3310
Medium 4.9

A vulnerability in the XML parser code of Cisco Firepower Device Manager On-Box software could allow an authenticated, remote attacker to cause an affected system to become unstable or reload. The vulnerability is due to insufficient hardening of the XML parse…

cisco firepower_device_manager_on-box
0.01EPSS
CVE-2018-15403
Medium 5.4

A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to …

cisco emergency_responder · cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service · cisco unity_connection
0.01EPSS
CVE-2017-6777
Medium 4.9

A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protection of sensitive files on the system. An a…

cisco elastic_services_controller
0.01EPSS
CVE-2013-5523
Medium 4.3

The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, relat…

cisco identity_services_engine_software
0.01EPSS
CVE-2018-0097
Medium 6.1

A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of the parameters in the …

cisco prime_infrastructure
0.01EPSS
CVE-2014-3267
Medium 6.8

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make unspecified changes, aka Bug ID CSCuo46427.

cisco security_manager
0.01EPSS
CVE-2020-3478
High 8.1

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device. The vulnerability is due to insufficient authoriza…

cisco enterprise_network_function_virtualization_infrastructure
0.01EPSS
CVE-2020-3345
Medium 4.3

A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values withi…

cisco webex_meetings · cisco webex_meetings_server
0.01EPSS
CVE-2019-1587
Medium 4.3

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly …

cisco nx-os
0.01EPSS
CVE-2019-1792
Medium 6.1

A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella. The vulnerability is due to insufficient validation of inp…

cisco umbrella
0.01EPSS
CVE-2019-1702
Medium 6.1

Multiple vulnerabilities in the web-based management interface of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affecte…

cisco enterprise_chat_and_email
0.01EPSS
CVE-2019-1685
Medium 6.1

A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affec…

cisco unity_connection
0.01EPSS
CVE-2019-1671
Medium 6.1

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected …

cisco secure_firewall_management_center
0.01EPSS
CVE-2019-1670
Medium 6.1

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vu…

cisco unified_intelligence_center
0.01EPSS
CVE-2019-1661
Medium 6.1

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of a…

cisco telepresence_management_suite
0.01EPSS
CVE-2019-1643
Medium 6.1

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. Th…

cisco prime_infrastructure
0.01EPSS
CVE-2018-15463
Medium 6.1

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability …

cisco identity_services_engine_software
0.01EPSS