imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2002-1024
High 7.1

Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

cisco catos · cisco css11000_content_services_switch · cisco ios · cisco pix_firewall_software
0.03EPSS
CVE-2019-1871
High 7.2

A vulnerability in the Import Cisco IMC configuration utility of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and implement arbitrary commands with root privileges on an…

cisco integrated_management_controller_supervisor · cisco unified_computing_system
0.03EPSS
CVE-2008-4390
High 7.5

The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by sniffing the net…

cisco linksys_wvc54gc_firmware
0.03EPSS
CVE-2019-15958
Critical 9.8

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulne…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.03EPSS
CVE-2018-0273
Medium 5.3

A vulnerability in the IPsec Manager of Cisco StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Routers and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and…

cisco staros
0.03EPSS
CVE-2011-0925
High 9.3

The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine, and execute this program, by identifying a Cisco program with a Cisco digital si…

cisco secure_desktop
0.03EPSS
CVE-2016-6385
High 7.5

Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2014-3327
High 7.8

The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCup52101.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2017-9479
Critical 9.8

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonstrated…

cisco dpc3939_firmware
0.03EPSS
CVE-2004-1434
Medium 5.0

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets.

cisco optical_networking_systems_software
0.03EPSS
CVE-2014-3380
Medium 5.0

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending crafted TCP packets quickly, aka Bug ID CSCuo42063.

cisco unified_communications_domain_manager_platform
0.03EPSS
CVE-2017-3819
High 8.8

A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, remote attacker to gain…

cisco asr_5000_series_software · cisco virtualized_packet_core
0.03EPSS
CVE-2017-9521
Critical 9.8

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC394…

cisco dpc3939_firmware · cisco dpc3939b_firmware · cisco dpc3941t_firmware · commscope arris_tg1682g_firmware
0.03EPSS
CVE-2022-20625
Medium 4.3

A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the service to restart, resulting in a denial of service (DoS) condition. This vulnerability is d…

cisco firepower_extensible_operating_system · cisco nx-os
0.03EPSS
CVE-2018-0286
Medium 5.3

A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system. The vulnerability is due to improper handling of malformed requests processed by …

cisco ios_xr
0.03EPSS
CVE-2002-1597
Medium 5.0

Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface.

cisco sn_5420_storage_router_firmware
0.03EPSS
CVE-2018-0152
High 8.8

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does not reset the privile…

cisco ios_xe
0.03EPSS
CVE-2019-15957
High 7.2

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When process…

cisco rv016_multi-wan_vpn_firmware · cisco rv042_dual_wan_vpn · cisco rv042g_dual_gigabit_wan_vpn_firmware · cisco rv082_dual_wan_vpn_router_firmware · and 2 more
0.03EPSS
CVE-2017-3832
High 7.5

A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a missing internal h…

cisco wireless_lan_controller_firmware
0.03EPSS
CVE-2012-0365
High 9.0

Directory traversal vulnerability in the Local TFTP file-upload application on Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allows remote authenticated users to upload software to arb…

cisco small_business_srp520-u_series_firmware · cisco small_business_srp520_series_firmware · cisco small_business_srp521w · cisco small_business_srp521w-u · and 8 more
0.03EPSS
CVE-2010-0641
Medium 4.3

Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

cisco collaboration_server
0.03EPSS
CVE-2017-12226
High 8.8

A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an …

cisco ios_xe
0.03EPSS
CVE-2007-0961
High 7.8

Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device…

cisco asa_5500 · cisco pix_firewall_software
0.03EPSS
CVE-2022-20841
Critical 9.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information ab…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · and 5 more
0.03EPSS
CVE-2018-0371
Medium 6.5

A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could expl…

cisco meeting_server
0.03EPSS