imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2011-0393
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1 and 7.2 before 7.2(5.2), 8.0 before 8.0(5.21), 8.1 before 8.1(2.49), 8.2 before 8.2(3.6), and 8.3 before 8.3(2.7) and Cisco PIX Security Appliances 500 series …

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500 · cisco pix_500
0.03EPSS
CVE-2011-0388
High 7.8

Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote a…

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software · cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.03EPSS
CVE-2010-4692
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) allows remote attackers to cause a denial of service (device crash) via a large number of LAN-to-LAN (aka L2L) IPsec sessions, aka Bug ID CSCt…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2010-4691
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) allows remote attackers to cause a denial of service (device crash) via multicast traffic, aka Bug IDs CSCtg61810 and CSCtg69742.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2010-4688
High 7.8

Unspecified vulnerability in the SIP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) allows remote attackers to cause a denial of service (device crash) by making many SIP calls, aka Bug ID CSCte20…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2010-4674
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allows remote attackers to cause a denial of service (block exhaustion) via multicast traffic, aka Bug ID CSCtg63992.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2010-4672
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier allow remote attackers to cause a denial of service (block exhaustion) via EIGRP traffic that triggers an EIGRP multicast storm, aka Bug ID CSCtf20269.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2015-4317
Medium 5.0

Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote attackers to cause a denial of service via invalid variables in an authentication packet, aka Bug ID CSCuv40469.

cisco telepresence_video_communication_server_software
0.03EPSS
CVE-2008-4444
High 7.1

Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol …

cisco unified_ip_phone_7940g · cisco unified_ip_phone_7960g
0.03EPSS
CVE-2019-1841
Medium 6.5

A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied in…

cisco catalyst_center
0.03EPSS
CVE-2010-4684
High 7.1

Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is enabled, allows remote attackers to cause a denial of service (device crash) via a TFTP copy over IPv6, aka Bug ID CSCtb28877.

cisco ios
0.03EPSS
CVE-2010-4673
High 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allow remote attackers to cause a denial of service via a flood of packets, aka Bug ID CSCtg06316.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2017-3857
High 7.5

A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.1 through 3.18) could allow an unauthenticated, remote attacker to cause an affected device to reload. The vuln…

cisco ios · cisco ios_xe
0.03EPSS
CVE-2005-4499
High 7.5

The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allow…

cisco adaptive_security_appliance_software · cisco pix_asa_ids · cisco pix_firewall · cisco pix_firewall_501 · and 17 more
0.03EPSS
CVE-2020-24587
Low 2.6

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when an…

arista c-100_firmware · arista c-110_firmware · arista c-120_firmware · arista c-130_firmware · and 164 more
0.03EPSS
CVE-2020-3269
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands. For more information about thes…

cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.03EPSS
CVE-2020-3268
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary commands. For more information about thes…

cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.03EPSS
CVE-2018-0322
High 8.8

A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modify sensitive data that is associated with arbitrary accounts on an affected device. The vulnerability is due to…

cisco prime_collaboration · cisco prime_collaboration_provisioning
0.03EPSS
CVE-2005-2105
High 7.5

Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.

cisco ios
0.03EPSS
CVE-2019-1675
High 7.5

A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static password. The account has privileges only t…

cisco aironet_active_sensor · cisco digital_network_architecture_center
0.03EPSS
CVE-2016-6392
High 7.5

Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2005-0186
Medium 5.0

Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to t…

cisco ios
0.03EPSS
CVE-2017-12280
High 7.5

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) Discovery Request parsing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly, re…

cisco wireless_lan_controller_software
0.03EPSS
CVE-2017-3830
High 7.5

A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678. Known Affected Releases: 2.1. Known Fixed…

cisco meeting_server
0.03EPSS
CVE-2016-6466
High 7.5

A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condi…

cisco asr_5000_series_software · cisco virtualized_packet_core
0.03EPSS