imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2019-1651
Critical 9.9

A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. The vulnerability is due to improper bounds checking by the v…

cisco vsmart_controller
0.05EPSS
CVE-2017-6667
Critical 9.8

A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server. M…

cisco context_service_development_kit
0.05EPSS
CVE-2018-0293
High 8.8

A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attacker to execute CLI commands that should be restricted for a nonadministrative user. The attacker would have to possess valid user credentials…

cisco nx-os
0.05EPSS
CVE-2018-0150
Critical 9.8

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vu…

cisco ios_xe
0.05EPSS
CVE-2009-2631
Medium 6.8

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway…

aladdin safenet_securewire_access_gateway · cisco adaptive_security_appliance · sonicwall e-class_ssl_vpn · sonicwall ssl_vpn · and 1 more
0.05EPSS
CVE-2016-1395
Critical 9.8

The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP …

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv130w_wireless-n_multifunction_vpn_router_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.05EPSS
CVE-2020-3119
High 8.8

A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Pr…

cisco nx-os · cisco ucs_manager
0.05EPSS
CVE-2016-6371
High 7.5

Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSCuz64717.

cisco hosted_collaboration_mediation_fulfillment
0.05EPSS
CVE-2010-0440
Medium 4.3

Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML …

cisco adaptive_security_appliance_software · cisco secure_desktop
0.05EPSS
CVE-2010-0589
High 9.3

The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted we…

cisco secure_desktop
0.05EPSS
CVE-2007-0481
High 7.8

Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.

cisco ios_transmission_control_protocol
0.05EPSS
CVE-2010-1574
High 10.0

IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or …

cisco industrial_ethernet_3000 · cisco ios
0.05EPSS
CVE-2007-2282
High 10.0

Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote attackers to modify the product configuration and, when installed on Linux, obtain login access to the host op…

cisco netflow_collection_engine
0.05EPSS
CVE-2019-1939
High 8.8

A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the applica…

cisco webex_teams
0.05EPSS
CVE-2014-3341
Medium 5.0

The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka…

cisco nexus_5000 · cisco nexus_5010 · cisco nexus_5010p_switch · cisco nexus_5020 · and 11 more
0.05EPSS
CVE-2011-2544
Low 3.5

Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site reque…

cisco telepresence_mxp_software · cisco telepresence_system_1000_mxp · cisco telepresence_system_1700_mxp
0.05EPSS
CVE-2011-0962
Medium 4.3

Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag …

cisco unified_operations_manager
0.05EPSS
CVE-2020-3258
Critical 9.8

Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local atta…

cisco ios
0.05EPSS
CVE-2019-1845
High 8.6

A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote att…

cisco telepresence_video_communication_server · cisco unified_communications_manager_im_and_presence_service
0.05EPSS
CVE-2018-0420
Medium 6.5

A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitization of user-supplied input in HTTP request parameters that d…

cisco wireless_lan_controller_software
0.05EPSS
CVE-2012-4655
High 9.3

The WebLaunch feature in Cisco Secure Desktop before 3.6.6020 does not properly validate binaries that are received by the downloader process, which allows remote attackers to execute arbitrary code via vectors involving (1) ActiveX or (2) Java components, aka…

cisco secure_desktop
0.05EPSS
CVE-2012-6392
High 10.0

Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc79779.…

cisco prime_lan_management_solution
0.05EPSS
CVE-2021-40113
Critical 10.0

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a de…

cisco catalyst_pon_switch_cgp-ont-1p_firmware · cisco catalyst_pon_switch_cgp-ont-4p_firmware · cisco catalyst_pon_switch_cgp-ont-4pv_firmware · cisco catalyst_pon_switch_cgp-ont-4pvc_firmware · and 1 more
0.05EPSS
CVE-2016-6393
High 7.5

The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an error-…

cisco ios · cisco ios_xe
0.05EPSS
CVE-2020-3470
Critical 9.8

Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certain us…

cisco enterprise_nfv_infrastructure_software · cisco integrated_management_controller
0.05EPSS