imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2012-4620
High 7.8

Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts668…

cisco 10008_router · cisco ios
0.03EPSS
CVE-2014-3319
Medium 6.8

Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup57676.

cisco unified_communications_manager
0.03EPSS
CVE-2021-34748
High 8.8

A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. A…

cisco intersight_virtual_appliance
0.03EPSS
CVE-2002-0882
Medium 6.4

The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the po…

cisco skinny_client_control_protocol_software · cisco voip_phone_cp-7940
0.03EPSS
CVE-2020-3573
High 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements …

cisco webex_meetings · cisco webex_meetings_server
0.03EPSS
CVE-2013-3385
High 7.8

The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and …

cisco ironport_asyncos
0.03EPSS
CVE-2012-0355
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers to cause a denial of service (device relo…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco catalyst_6500 · cisco catalyst_6503-e · and 7 more
0.03EPSS
CVE-2015-6335
High 9.0

The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to bypass intended policy restrictions and execute Linux commands as root via unspecified vectors, aka Bug ID CSCuw…

cisco firesight_system_software
0.03EPSS
CVE-2001-1434
Medium 5.0

Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.

cisco ios
0.03EPSS
CVE-2015-4204
Medium 6.8

Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug I…

cisco cisco_ios
0.03EPSS
CVE-2018-0285
Medium 6.5

A vulnerability in service logging for Cisco Prime Service Catalog could allow an authenticated, remote attacker to deny service to the user interface. The vulnerability is due to exhaustion of disk space. An attacker could exploit this vulnerability by perfor…

cisco prime_service_catalog
0.03EPSS
CVE-2016-1374
High 8.8

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.

cisco unified_computing_system_performance_manager
0.03EPSS
CVE-2008-2059
High 7.8

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors.

cisco adaptive_security_appliance_software · cisco pix_security_appliance
0.03EPSS
CVE-2010-0146
Medium 6.8

Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.

cisco security_agent
0.03EPSS
CVE-2006-0340
High 7.1

Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network …

cisco ios
0.03EPSS
CVE-2018-0377
Critical 9.8

A vulnerability in the Open Systems Gateway initiative (OSGi) interface of Cisco Policy Suite before 18.1.0 could allow an unauthenticated, remote attacker to directly connect to the OSGi interface. The vulnerability is due to a lack of authentication. An atta…

cisco mobility_services_engine · cisco policy_suite
0.03EPSS
CVE-2018-0376
Critical 9.8

A vulnerability in the Policy Builder interface of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to access the Policy Builder interface. The vulnerability is due to a lack of authentication. An attacker could exploit this vul…

cisco mobility_services_engine · cisco policy_suite
0.03EPSS
CVE-2018-0374
Critical 9.8

A vulnerability in the Policy Builder database of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to connect directly to the Policy Builder database. The vulnerability is due to a lack of authentication. An attacker could explo…

cisco mobility_services_engine
0.03EPSS
CVE-2012-4618
High 7.8

The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183.

cisco ios
0.03EPSS
CVE-2011-2578
High 7.8

Memory leak in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption) via malformed SIP packets on a NAT interface, aka Bug ID CSCts12366.

cisco ios
0.03EPSS
CVE-2012-1310
High 7.8

Memory leak in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted IP packets, aka Bug ID CSCto89536.

cisco ios
0.03EPSS
CVE-2021-1560
Medium 6.5

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands.…

cisco dna_spaces\
0.03EPSS
CVE-2021-1559
Medium 6.5

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands.…

cisco dna_spaces\
0.03EPSS
CVE-2021-1362
High 8.8

A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License M…

cisco prime_license_manager · cisco unified_communications_manager · cisco unified_communications_manager_im_\&_presence_service · cisco unity_connection
0.03EPSS
CVE-2018-0391
Medium 6.5

A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to cause the system to become inoperable. The vulnerability is due to insufficient validation of a password change request. …

cisco prime_collaboration · cisco prime_collaboration_provisioning
0.03EPSS