imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2015-6406
Medium 4.0

Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.

cisco emergency_responder
0.02EPSS
CVE-2014-3323
Medium 4.0

Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262.

cisco unified_contact_center_enterprise
0.02EPSS
CVE-2009-2872
Medium 6.8

Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel t…

cisco ios
0.02EPSS
CVE-2008-2062
Medium 5.0

The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statisti…

cisco unified_communications_manager
0.02EPSS
CVE-2020-3299
Medium 5.8

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of modified HTTP packets use…

cisco secure_firewall_threat_defense · snort snort
0.02EPSS
CVE-2009-0619
High 7.8

Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000.

cisco session_border_controller
0.02EPSS
CVE-2018-0139
High 8.6

A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of se…

cisco unified_customer_voice_portal
0.02EPSS
CVE-2014-0661
High 8.3

The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of s…

cisco telepresence_system_1000 · cisco telepresence_system_1100 · cisco telepresence_system_1300-65 · cisco telepresence_system_3000 · and 10 more
0.02EPSS
CVE-2017-6626
Medium 5.3

A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is…

cisco unified_contact_center_enterprise
0.02EPSS
CVE-2015-0678
High 7.8

The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the…

cisco asa_cx_context-aware_security_software · cisco asa_with_firepower_services
0.02EPSS
CVE-2019-1711
Medium 5.3

A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC req…

cisco ios_xr
0.02EPSS
CVE-2019-1644
High 7.5

A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to exhaust system resources, resulting in a denial of service (DoS) condition. The vulnerability is due to imprope…

cisco iot_field_network_director
0.02EPSS
CVE-2018-0369
High 8.6

A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could allow an unauthenticated, remote attacker to trigger a reload of the npusim process, resulting in a denial of service (DoS) condition. There …

cisco staros
0.02EPSS
CVE-2022-20704
Critical 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · and 5 more
0.02EPSS
CVE-2018-0132
High 8.6

A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB) and the FIB, resulting in a denial of service (DoS) conditi…

cisco carrier_routing_system
0.02EPSS
CVE-2018-0094
High 7.5

A vulnerability in IPv6 ingress packet processing for Cisco UCS Central Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high CPU utilization on the targeted device. The vulnerability is due to insuff…

cisco unified_computing_system_central_software
0.02EPSS
CVE-2018-0086
High 8.6

A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE tra…

cisco unified_customer_voice_portal
0.02EPSS
CVE-2017-12293
High 8.6

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected soft…

cisco webex_meetings_server
0.02EPSS
CVE-2017-12260
High 7.5

A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, res…

cisco spa_501g_firmware · cisco spa_502g_firmware · cisco spa_504g_firmware · cisco spa_508g_firmware · and 4 more
0.02EPSS
CVE-2017-12259
High 7.5

A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial o…

cisco small_business_ip_phone_firmware
0.02EPSS
CVE-2017-12270
High 7.5

A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the emsd service stops. The vulnerability…

cisco ios_xr
0.02EPSS
CVE-2017-6729
High 7.5

A vulnerability in the Border Gateway Protocol (BGP) processing functionality of the Cisco StarOS operating system for Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core (VPC) Software could allow an unauthenticated, remote attacker to cause the B…

cisco asr_5000_software
0.02EPSS
CVE-2013-5511
High 10.0

The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2020-3382
Critical 9.8

A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists be…

cisco data_center_network_manager
0.02EPSS
CVE-2013-1137
High 7.8

Cisco Unified Presence Server (CUPS) 8.6, 9.0, and 9.1 before 9.1.1 allows remote attackers to cause a denial of service (CPU consumption) via crafted packets to the SIP TCP port, aka Bug ID CSCua89930.

cisco unified_presence_server
0.02EPSS