imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2013-5481
High 7.1

The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817.

cisco ios
0.02EPSS
CVE-2008-3818
High 7.8

Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted TCP session.

cisco ons · cisco ons_15600
0.02EPSS
CVE-2021-1313
High 8.6

Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, se…

cisco ios_xr
0.02EPSS
CVE-2021-1288
High 8.6

Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, se…

cisco ios_xr
0.02EPSS
CVE-2015-0751
High 7.8

Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3375
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90597.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3374
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90582.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3373
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCup9255…

cisco unified_communications_manager
0.02EPSS
CVE-2014-3372
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90589.

cisco unified_communications_manager
0.02EPSS
CVE-2014-3344
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified pa…

cisco transport_gateway_installation_software
0.02EPSS
CVE-2014-3313
Medium 4.3

Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.

cisco spa901_1-line_ip_phone · cisco spa922_1-line_ip_phone_with_1-port_ethernet · cisco spa941_4-line_ip_phone_with_1-port_ethernet · cisco spa942_4-line_ip_phone_with_2-port_switch · and 12 more
0.02EPSS
CVE-2014-0680
Medium 4.3

Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.

cisco identity_services_engine
0.02EPSS
CVE-2013-6960
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248.

cisco webex_meeting_center
0.02EPSS
CVE-2007-4293
High 7.1

Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505.

cisco ios
0.02EPSS
CVE-2021-1259
Medium 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain write access to sensitive files on an affected system. The vulnerability is due to…

cisco sd-wan_vmanage
0.02EPSS
CVE-2014-0722
Medium 5.0

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCu…

cisco unified_communications_manager
0.02EPSS
CVE-2014-0662
High 7.1

The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632.

cisco telepresence_video_communication_server_software · cisco telepresence_video_communication_servers_software
0.02EPSS
CVE-2014-0660
High 7.1

Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360.

cisco telepresence_isdn_gateway_software
0.02EPSS
CVE-2016-1367
High 7.5

The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248.

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2016-1348
High 7.5

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.

cisco ios_xe · netgear jr6150_firmware · samsung x14j_firmware · sun opensolaris · and 2 more
0.02EPSS
CVE-2015-4196
Medium 5.0

Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH se…

cisco unified_communications_domain_manager
0.02EPSS
CVE-2015-0764
Medium 5.0

Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.

cisco unified_meetingplace
0.02EPSS
CVE-2015-0763
Medium 5.0

Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.

cisco unified_meetingplace
0.02EPSS
CVE-2015-0745
Medium 5.0

Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909.

cisco headend_digital_broadband_delivery_system · cisco headend_system_release
0.02EPSS
CVE-2012-4087
Medium 5.1

A cluster setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20793.

cisco unified_computing_system
0.02EPSS