imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2004-0710
Medium 5.0

IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (devi…

cisco ios
0.02EPSS
CVE-2021-1224
Medium 5.8

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due…

cisco ios_xe · cisco meraki_mx100_firmware · cisco meraki_mx250_firmware · cisco meraki_mx450_firmware · and 12 more
0.02EPSS
CVE-2015-6340
Medium 5.0

The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.60737 allows remote attackers to cause a denial of service (hamgr process restart) via a crafted header in a PMIPv6 packet, aka Bug ID CSCuv6328…

cisco asr_5000_software
0.02EPSS
CVE-2015-6332
Medium 5.0

Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug ID CSCuv56830.

cisco prime_infrastructure
0.02EPSS
CVE-2013-3402
Medium 6.5

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440.

cisco unified_communications_manager
0.02EPSS
CVE-2018-0282
Medium 6.8

A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a state condition between the socket state and the transmission control b…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2014-2112
High 7.8

The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.

cisco ios
0.02EPSS
CVE-2015-0636
High 7.8

The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN mes…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2019-1908
High 7.5

A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficien…

cisco integrated_management_controller_supervisor · cisco unified_computing_system
0.02EPSS
CVE-2018-0248
Medium 6.8

A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using…

cisco wireless_lan_controller_software
0.02EPSS
CVE-2015-6271
High 7.8

Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008…

cisco ios_xe
0.02EPSS
CVE-2014-3393
Medium 4.3

The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement …

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2010-0151
High 7.8

The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Cli…

cisco firewall_services_module
0.02EPSS
CVE-2010-0142
High 8.5

MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530.

cisco unified_meetingplace
0.02EPSS
CVE-2002-2140
Medium 5.0

Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.

cisco pix_firewall_software
0.02EPSS
CVE-2016-1402
High 7.5

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Passw…

cisco identity_services_engine_software
0.02EPSS
CVE-2015-4233
Medium 6.5

SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.

cisco unified_meetingplace
0.02EPSS
CVE-2015-4222
Medium 6.5

SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.

cisco unified_communications_manager_im_and_presence_service
0.02EPSS
CVE-2011-2581
Medium 5.0

The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000 series switches, does not properly handle comments in conjunction with deny statements, which allows remote at…

cisco nexus_3000 · cisco nexus_5000 · cisco nx-os
0.02EPSS
CVE-2014-3270
Medium 5.0

The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.

cisco ios_xr
0.02EPSS
CVE-2015-6341
Medium 5.0

The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.

cisco wireless_lan_controller_software
0.02EPSS
CVE-2015-6334
Medium 5.0

Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process restart) via a crafted header in a TACACS packet, aka Bug ID CSCuw01984.

cisco asr_5000_software
0.02EPSS
CVE-2015-4273
Medium 5.0

The Packet Data Network Gateway (aka PGW) component on Cisco ASR 5000 devices with software 15.0(912), 15.0(935), and 15.0(938) allows remote attackers to cause a denial of service (Session Manager outage) via malformed fields in an IP packet, aka Bug ID CSCut…

cisco asr_5000_series_software
0.02EPSS
CVE-2015-0765
Medium 5.0

Cisco ONS 15454 System Software 10.30 and 10.301 allows remote attackers to cause a denial of service (tNetTask CPU consumption or card reset) via a flood of (1) IP or (2) Ethernet traffic, aka Bug ID CSCus57263.

cisco ons_15454_system_software
0.02EPSS
CVE-2015-0743
Medium 5.0

Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097.

cisco headend_digital_broadband_delivery_system · cisco headend_system_release
0.02EPSS