imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2017-6639
Critical 9.8

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affecte…

cisco prime_data_center_network_manager
0.35EPSS
CVE-2000-0380
High 7.1

The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

cisco ios
0.35EPSS
CVE-2024-20290
High 7.5

A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scan…

cisco secure_endpoint · cisco secure_endpoint_private_cloud · fedoraproject fedora
0.34EPSS
CVE-2008-4609
High 7.1

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that m…

bsd bsd · bsdi bsd_os · cisco catalyst_blade_switch_3020_firmware · cisco catalyst_blade_switch_3120_firmware · and 15 more
0.32EPSS
CVE-1999-0524
Medium 4.0

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

apple mac_os_x · apple macos · cisco ios · hp hp-ux · and 10 more
0.32EPSS
CVE-2022-20964
Medium 6.3

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user i…

cisco identity_services_engine
0.31EPSS
CVE-2021-1531
High 8.8

A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling Labs server. This vulne…

cisco modeling_labs
0.30EPSS
CVE-2023-20128
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an …

cisco rv320_firmware · cisco rv325_firmware
0.30EPSS
CVE-2019-1867
Critical 10.0

A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this…

cisco elastic_services_controller
0.30EPSS
CVE-2024-20337
High 8.2

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of…

cisco secure_client
0.30EPSS
CVE-2019-1621
High 7.5

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions setting…

cisco data_center_network_manager
0.30EPSS
CVE-2023-20032
Critical 9.8

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated,…

cisco secure_endpoint · cisco secure_endpoint_private_cloud · cisco web_security_appliance · clamav clamav · and 1 more
0.29EPSS
CVE-2022-20759
High 8.8

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privil…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.29EPSS
CVE-2019-12650
High 8.8

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see …

cisco ios · cisco ios_xe
0.29EPSS
CVE-2009-1558
High 7.8

Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parame…

cisco wvc54gca
0.29EPSS
CVE-2008-0533
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web scrip…

cisco acs_for_windows · cisco acs_solution_engine · cisco user_changeable_password
0.29EPSS
CVE-2020-10136
Medium 5.3

IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets…

cisco nx-os · cisco ucs_manager · cisco unified_computing_system · digi saros · and 2 more
0.29EPSS
CVE-2023-20117
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an …

cisco rv320_firmware · cisco rv325_firmware
0.28EPSS
CVE-2022-20966
Medium 5.4

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnera…

cisco identity_services_engine
0.28EPSS
CVE-2017-3823
High 8.8

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Dow…

cisco activetouch_general_plugin_container · cisco download_manager · cisco gpccontainer_class · cisco webex · and 2 more
0.27EPSS
CVE-2014-7992
Medium 5.0

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

cisco ios
0.27EPSS
CVE-2025-20188
Critical 10.0

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload …

cisco ios_xe
0.27EPSS
CVE-2025-20282
Critical 10.0

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is …

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.27EPSS
CVE-2011-3315
High 7.8

Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voi…

cisco unified_communications_manager · cisco unified_ip_interactive_voice_response · cisco unified_ip_ivr
0.26EPSS
CVE-2019-1913
Critical 9.8

Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the under…

cisco sf-220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · and 7 more
0.26EPSS