IT

Cisco vulnerabilities

6647 CVE

CVE-2012-0364
High 7.8

Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to replace the configuration file via an upload request to an unspecified URL, aka Bug ID CSCtw55495.

cisco small_business_srp520-u_series_firmware · cisco small_business_srp520_series_firmware · cisco small_business_srp521w · cisco small_business_srp521w-u · and 8 more
0.01EPSS
CVE-2016-1444
Medium 6.5

The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted cert…

cisco telepresence_video_communication_server · cisco telepresence_video_communication_server_software
0.01EPSS
CVE-2015-6305
High 7.2

Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working dir…

cisco anyconnect_secure_mobility_client
0.01EPSS
CVE-2005-1517
High 7.5

Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).

cisco firewall_services_module
0.01EPSS
CVE-2017-6670
Medium 6.1

A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8…

cisco unified_communications_domain_manager
0.01EPSS
CVE-2017-6604
Medium 6.1

A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC …

cisco unified_computing_system
0.01EPSS
CVE-2022-20757
High 8.6

A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper traff…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2019-12623
Medium 4.3

A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to th…

cisco enterprise_network_functions_virtualization_infrastructure
0.01EPSS
CVE-2018-15406
Medium 6.1

A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vu…

cisco ucs_director
0.01EPSS
CVE-2013-1120
Medium 6.8

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910.

cisco unity_express · cisco unity_express_software
0.01EPSS
CVE-2021-1486
Medium 5.3

A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticat…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.01EPSS
CVE-2021-1493
High 8.5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerabilit…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2019-1692
Medium 5.3

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of prop…

cisco application_policy_infrastructure_controller
0.01EPSS
CVE-2018-15397
Medium 6.8

A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause …

cisco adaptive_security_appliance_software · cisco secure_firewall_management_center
0.01EPSS
CVE-2015-6411
Medium 5.0

Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.

cisco secure_firewall_management_center
0.01EPSS
CVE-2014-0708
Medium 5.0

WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) a browser's histor…

cisco webex_meeting_center
0.01EPSS
CVE-2010-4304
Medium 6.4

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing…

cisco unified_videoconferencing_system_3515_multipoint_control_unit · cisco unified_videoconferencing_system_3515_multipoint_control_unit_firmware · cisco unified_videoconferencing_system_3522_basic_rate_interface_gateway · cisco unified_videoconferencing_system_3522_basic_rate_interface_gateway_firmware · and 10 more
0.01EPSS
CVE-2019-15990
Medium 5.3

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper au…

cisco rv016_multi-wan_vpn_firmware · cisco rv042_dual_wan_vpn_firmware · cisco rv042g_dual_gigabit_wan_vpn_firmware · cisco rv082_dual_wan_vpn_firmware
0.01EPSS
CVE-2021-1616
Medium 4.7

A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data valida…

cisco ios_xe
0.01EPSS
CVE-2020-3256
Medium 4.9

A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vu…

cisco hosted_collaboration_mediation_fulfillment
0.01EPSS
CVE-2021-1484
Medium 6.5

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and cause a denial of service (DoS) condition. This vulnerability is due to improper input val…

cisco catalyst_sd-wan_manager
0.01EPSS
CVE-2007-1467
Low 3.5

Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallMana…

cisco acs_solution_engine · cisco call_manager · cisco ciscoworks · cisco ip_communicator · and 14 more
0.01EPSS
CVE-2018-0210
High 8.8

A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerabil…

cisco data_center_network_manager
0.01EPSS
CVE-2014-8005
Medium 5.0

Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.

cisco ios_xr
0.01EPSS
CVE-2013-3424
Medium 6.8

Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCud75177.

cisco secure_access_control_system
0.01EPSS