imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2017-6643
Medium 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Directory information on an affected system. The vulnerability exists because the affected software …

cisco remote_expert_manager
0.03EPSS
CVE-2017-6642
Medium 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficien…

cisco remote_expert_manager
0.03EPSS
CVE-2014-0658
Medium 5.4

Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.

cisco unified_ip_phone_9951 · cisco unified_ip_phone_9971 · cisco unified_ip_phones_9900_series_firmware
0.03EPSS
CVE-2017-12219
High 7.5

A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) conditio…

cisco spa_301_firmware · cisco spa_303_firmware · cisco spa_500ds_firmware · cisco spa_500s_firmware · and 7 more
0.03EPSS
CVE-2016-9225
High 8.6

A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a…

cisco asa_cx_context-aware_security_software
0.03EPSS
CVE-2009-1157
High 7.8

Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (mem…

cisco adaptive_security_appliance_5500 · cisco pix
0.03EPSS
CVE-2018-0403
Critical 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.

cisco unified_contact_center_express · cisco unified_ip_interactive_voice_response
0.03EPSS
CVE-2016-1365
High 8.8

The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.

cisco application_policy_infrastructure_controller_enterprise_module
0.03EPSS
CVE-2017-6750
High 7.5

A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the we…

cisco web_security_appliance · cisco web_security_virtual_appliance
0.03EPSS
CVE-2008-3803
Medium 5.1

A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in…

cisco ios
0.03EPSS
CVE-2005-3788
Medium 5.4

Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) b…

cisco adaptive_security_appliance_software
0.03EPSS
CVE-2020-3401
Medium 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to …

cisco sd-wan_firmware
0.03EPSS
CVE-2018-0090
High 7.5

A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to th…

cisco nx-os
0.03EPSS
CVE-2014-0649
High 9.0

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.

cisco secure_access_control_system
0.03EPSS
CVE-2020-3381
High 8.8

A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is…

cisco sd-wan_firmware
0.03EPSS
CVE-2015-4307
High 9.0

The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111.

cisco prime_collaboration_provisioning
0.03EPSS
CVE-2015-4304
High 9.0

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug I…

cisco prime_collaboration_assurance
0.03EPSS
CVE-2018-0271
Critical 9.8

A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and access critical services. The vulnerability is due to a failure to normalize URLs prior to se…

cisco digital_network_architecture_center
0.03EPSS
CVE-2012-0367
High 7.8

Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.

cisco unity_connection
0.03EPSS
CVE-2019-1869
High 8.6

A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of s…

cisco staros
0.03EPSS
CVE-2019-1712
Medium 5.8

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device. The vulnerabilit…

cisco ios_xr
0.03EPSS
CVE-2018-0288
Medium 5.3

A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance a…

cisco webex_meetings_online
0.03EPSS
CVE-2017-6619
High 8.8

A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not suff…

cisco integrated_management_controller_supervisor
0.03EPSS
CVE-2008-2736
High 7.1

Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug…

cisco adaptive_security_appliance_5500
0.03EPSS
CVE-2015-6357
Medium 6.8

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, …

cisco firesight_system_software
0.03EPSS