imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2016-6416
Medium 5.9

The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a…

cisco content_security_management_appliance · cisco email_security_appliance · cisco web_security_appliance
0.02EPSS
CVE-2015-0591
Medium 5.0

Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka Bug ID CSCur44177.

cisco unified_communications_domain_manager
0.02EPSS
CVE-2015-0579
Medium 5.0

Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumption, and partial outage) via crafted SIP packets, aka Bug ID CSCur12473.

cisco telepresence_video_communication_server
0.02EPSS
CVE-2012-5416
High 7.8

Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of service (daemon hang) via unspecified parameters in a POST request, aka Bug ID C…

cisco unified_meetingplace
0.02EPSS
CVE-2016-9207
Medium 6.5

A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This …

cisco expressway
0.02EPSS
CVE-2021-1468
Critical 9.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2002-1596
Medium 5.0

Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers.

cisco sn_5420_storage_router_firmware
0.02EPSS
CVE-2014-0656
Medium 4.0

Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface data via crafted field values, aka Bug ID CSCuj45353.

cisco context_directory_agent
0.02EPSS
CVE-2014-0703
High 10.0

Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by connecting to an Air…

cisco wireless_lan_controller · cisco wireless_lan_controller_software
0.02EPSS
CVE-2013-7043
High 8.3

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Passw…

cisco scientific_atlanta__dpr2325 · cisco scientific_atlanta__dpr2325_firmware · cisco scientific_atlanta__dpr\/epr2320 · cisco scientific_atlanta__dpr\/epr2320_firmware
0.02EPSS
CVE-2018-15422
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15421
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15419
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15418
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_31 · cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · and 1 more
0.02EPSS
CVE-2018-15411
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15410
High 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_31 · cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · and 1 more
0.02EPSS
CVE-2014-3398
Medium 5.0

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-version information by reading the verbose response data that is provided for a request to an unspecified URL, aka B…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2018-0346
High 7.5

A vulnerability in the Zero Touch Provisioning service of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect bounds checks for cert…

cisco vbond_orchestrator · cisco vedge-1000_firmware · cisco vedge-100_firmware · cisco vedge-2000_firmware · and 8 more
0.02EPSS
CVE-2016-6462
Medium 5.3

A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. T…

cisco email_security_appliance_firmware
0.02EPSS
CVE-2018-0357
Medium 6.1

A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input valid…

cisco webex_meetings
0.02EPSS
CVE-2009-5040
Medium 6.8

CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.

cisco ios
0.02EPSS
CVE-2010-0139
High 9.0

Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.

cisco unified_meetingplace
0.02EPSS
CVE-2015-0739
Medium 4.0

The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug I…

cisco firesight_system_software
0.02EPSS
CVE-2018-15444
Medium 6.3

A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper hand…

cisco energy_management_suite_software
0.02EPSS
CVE-2013-5557
Medium 6.3

The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request …

cisco adaptive_security_appliance_software
0.02EPSS