imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2007-0959
High 7.8

Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.

cisco asa_5500 · cisco pix_firewall_software
0.02EPSS
CVE-2013-5530
High 9.0

The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to…

cisco identity_services_engine_software
0.02EPSS
CVE-2011-2395
Medium 5.0

The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router Advertisement (RA) message is contained …

cisco ios
0.02EPSS
CVE-2018-15453
High 8.6

A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker…

cisco email_security_appliance_firmware
0.02EPSS
CVE-2015-4329
Medium 6.5

The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796.

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2019-1895
Critical 9.8

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected dev…

cisco enterprise_network_function_virtualization_infrastructure
0.02EPSS
CVE-2013-5498
Medium 5.0

The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963.

cisco ios_xr
0.02EPSS
CVE-2020-3147
High 7.5

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web inter…

cisco sf300-08_firmware · cisco sf300-24_firmware · cisco sf300-24mp_firmware · cisco sf300-24p_firmware · and 53 more
0.02EPSS
CVE-2011-3290
High 10.0

Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.

cisco identity_services_engine · cisco identity_services_engine_software
0.02EPSS
CVE-2015-4306
High 8.5

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier…

cisco prime_collaboration_assurance
0.02EPSS
CVE-2024-20401
Critical 9.8

A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handl…

cisco secure_email_gateway
0.02EPSS
CVE-2012-0366
High 9.0

Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141.

cisco unity_connection
0.02EPSS
CVE-2018-0447
Medium 5.3

A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass certain content filters on an affected device. The vulnerability is due to i…

cisco email_security_appliance
0.02EPSS
CVE-2017-6692
High 8.8

A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vulnerability. More Information: CSCvd8571…

cisco ultra_services_framework_element_manager
0.02EPSS
CVE-2017-6688
High 8.8

A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. More Information: CSCvc76631. Known Affected Releases: 2…

cisco elastic_services_controller
0.02EPSS
CVE-2017-6684
High 8.8

A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Release…

cisco elastic_services_controller
0.02EPSS
CVE-2014-0671
Medium 5.8

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

cisco mediasense
0.02EPSS
CVE-2014-0654
Medium 4.3

Cisco Context Directory Agent (CDA) allows remote attackers to modify the cache via a replay attack involving crafted RADIUS accounting messages, aka Bug ID CSCuj45383.

cisco context_directory_agent
0.02EPSS
CVE-2019-1691
Medium 5.8

A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition. The vulnerabilit…

cisco secure_firewall_threat_defense
0.02EPSS
CVE-2018-15464
Medium 5.8

A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of cert…

cisco asr_900_series_software
0.02EPSS
CVE-2011-0348
Medium 6.4

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended acce…

cisco ios
0.02EPSS
CVE-2021-1443
Medium 5.5

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software…

cisco ios_xe
0.02EPSS
CVE-2011-1607
Medium 6.5

Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary …

cisco unified_communications_manager
0.02EPSS
CVE-2008-2055
High 7.8

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.x before 7.2(4), and 8.0.x before 8.0(3)10 allows remote attackers to cause a denial of service via a crafted TCP ACK packet to the device interface.

cisco adaptive_security_appliance_software · cisco pix_security_appliance
0.02EPSS
CVE-2021-1433
High 8.1

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic…

cisco ios_xe
0.02EPSS