imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2026-20316
Exploited Medium 5.3

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. …

cisco secure_firewall_management_center
0.01EPSS
CVE-2019-1821
High 8.8

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating s…

cisco evolved_programmable_network_manager · cisco network_level_service · cisco prime_infrastructure
0.98EPSS
CVE-2021-44832
Medium 6.6

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of…

apache log4j · cisco cloudcenter · debian debian_linux · fedoraproject fedora · and 18 more
0.98EPSS
CVE-2020-3187
Critical 9.1

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delet…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · and 10 more
0.97EPSS
CVE-2019-15975
Critical 9.8

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. F…

cisco data_center_network_manager
0.96EPSS
CVE-1999-0016
Medium 5.0

Land IP denial of service.

cisco ios · gnu inet · hp hp-ux · microsoft windows_95 · and 4 more
0.96EPSS
CVE-2019-1663
Critical 9.8

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary cod…

cisco rv110w_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.96EPSS
CVE-2016-2183
High 7.5

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack…

cisco content_security_management_appliance · nodejs node.js · openssl openssl · oracle database · and 5 more
0.96EPSS
CVE-2019-15976
Critical 9.8

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. F…

cisco data_center_network_manager
0.93EPSS
CVE-2023-20073
Medium 5.3

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insuffici…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.89EPSS
CVE-2020-3243
Critical 9.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.88EPSS
CVE-2020-27131
High 8.1

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization …

cisco security_manager
0.88EPSS
CVE-2018-15381
Critical 9.8

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied co…

cisco unity_express
0.87EPSS
CVE-2018-0101
Critical 10.0

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.87EPSS
CVE-2018-15379
Critical 9.8

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the p…

cisco prime_infrastructure
0.86EPSS
CVE-2019-1620
Critical 9.8

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due to incorrect permission settings in affe…

cisco data_center_network_manager
0.84EPSS
CVE-2019-1935
Critical 9.8

A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account…

cisco integrated_management_controller_supervisor · cisco ucs_director · cisco ucs_director_express_for_big_data
0.83EPSS
CVE-2019-1619
Critical 9.8

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The v…

cisco data_center_network_manager
0.83EPSS
CVE-2005-0356
Medium 5.0

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host t…

alaxala alaxala_networks · cisco agent_desktop · cisco aironet_ap1200 · cisco aironet_ap350 · and 72 more
0.83EPSS
CVE-2024-20419
Critical 10.0

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper impl…

cisco smart_software_manager_on-prem
0.81EPSS
CVE-2021-1499
Medium 5.3

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An att…

cisco hyperflex_hx_data_platform
0.80EPSS
CVE-2002-1359
High 10.0

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol …

cisco ios · fissh ssh_client · intersoft securenetterm · netcomposite shellguard_ssh · and 3 more
0.80EPSS
CVE-2022-20705
Critical 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · and 5 more
0.80EPSS
CVE-2020-16139
High 7.5

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, th…

cisco unified_ip_conference_station_7937g_firmware
0.80EPSS
CVE-2019-1622
Medium 5.3

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerability is due to improper access controls fo…

cisco data_center_network_manager
0.79EPSS