imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2014-3361
High 7.1

The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.

cisco ios
0.02EPSS
CVE-2020-3361
High 8.1

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerab…

cisco webex_meetings · cisco webex_meetings_server
0.02EPSS
CVE-2018-15465
High 8.1

A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnera…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2013-5469
High 7.1

The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED state, which allows remote attackers to cause a denial of service (flood of ACK packets) via a crafted series of ACK and FIN packets, aka B…

cisco ios
0.02EPSS
CVE-2001-0650
Medium 5.0

Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.

cisco ios
0.02EPSS
CVE-2015-4280
Medium 5.0

Cisco Prime Collaboration Assurance 10.0 allows remote attackers to cause a denial of service (HTTP service outage) via a crafted HTTP request, aka Bug ID CSCum38844.

cisco prime_collaboration
0.02EPSS
CVE-2015-4271
Medium 6.4

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv00604.

cisco telepresence_tc_software
0.02EPSS
CVE-2018-0204
High 7.5

A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacke…

cisco prime_collaboration_provisioning
0.02EPSS
CVE-2017-6662
High 8.0

A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker read and write access to information stored in the affected system as well as perfo…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.02EPSS
CVE-2016-1455
High 7.5

Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attackers to obtain sensitive information via TCP or UDP traffic, aka Bug ID CSCuz05365.

cisco nx-os
0.02EPSS
CVE-2020-3125
Critical 9.8

A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · and 9 more
0.02EPSS
CVE-2010-2026
Medium 6.4

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.

cisco scientific_atlanta_webstar_dpc2100r2
0.02EPSS
CVE-2006-3290
Medium 5.0

HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL req…

cisco wireless_control_system
0.02EPSS
CVE-2008-4544
Medium 5.0

Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error."

cisco unity
0.02EPSS
CVE-2007-1833
Medium 5.0

The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services…

cisco unified_callmanager
0.02EPSS
CVE-2007-0962
High 7.8

Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot)…

cisco asa_5500 · cisco firewall_services_module · cisco pix_firewall_software
0.02EPSS
CVE-2016-1461
High 7.5

Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.

cisco asyncos
0.02EPSS
CVE-2015-4240
Medium 5.0

Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified URL in a GET request, aka Bug ID CSCuu37656.

cisco ip_communicator
0.02EPSS
CVE-2015-6284
High 7.8

Buffer overflow in the Conference Control Protocol API implementation in Cisco TelePresence Server software before 4.1(2.33) on 7010, MSE 8710, Multiparty Media 310 and 320, and Virtual Machine devices allows remote attackers to cause a denial of service (devi…

cisco telepresence_server_software
0.02EPSS
CVE-2019-12648
High 8.8

A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect ro…

cisco ios
0.02EPSS
CVE-2001-0895
Medium 5.0

Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to o…

cisco catalyst_2900xl · cisco catalyst_2948g-l3 · cisco catalyst_2950 · cisco catalyst_3500xl · and 7 more
0.02EPSS
CVE-2017-12362
Medium 6.5

A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a …

cisco meeting_server
0.02EPSS
CVE-2011-2583
Medium 5.0

Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.

cisco unified_contact_center_express
0.02EPSS
CVE-2005-2025
Medium 5.0

Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response…

cisco vpn_3000_concentrator · cisco vpn_3000_concentrator_series_software · cisco vpn_3005_concentrator_software · cisco vpn_3015_concentrator · and 4 more
0.02EPSS
CVE-2004-1111
Medium 5.0

Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause…

cisco 7200_router · cisco 7300_router · cisco 7500_router · cisco 7600_router · and 6 more
0.02EPSS