imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2015-4289
Medium 6.4

Directory traversal vulnerability in Cisco AnyConnect Secure Mobility Client 4.0(2049) allows remote head-end systems to write to arbitrary files via a crafted configuration attribute, aka Bug ID CSCut93920.

cisco anyconnect_secure_mobility_client
0.02EPSS
CVE-2015-6292
High 7.8

The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of servi…

cisco web_security_appliance
0.02EPSS
CVE-2015-6293
High 7.8

Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple…

cisco web_security_appliance
0.02EPSS
CVE-2015-6291
High 7.8

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, d…

cisco email_security_appliance
0.02EPSS
CVE-2015-6270
High 7.8

Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.

cisco ios_xe
0.02EPSS
CVE-2015-6269
High 7.8

Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted (1) IPv4 or (2) IPv6 packet, aka Bug ID CSCsw69990.

cisco ios_xe
0.02EPSS
CVE-2009-0628
High 9.0

Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) lea…

cisco cisco_ios
0.02EPSS
CVE-2008-0026
Medium 6.5

SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user int…

cisco unified_callmanager · cisco unified_communications_manager
0.02EPSS
CVE-2014-2128
Medium 5.0

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication v…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-6792
Medium 6.5

A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in BatchFil…

cisco prime_collaboration_provisioning
0.02EPSS
CVE-2020-3436
High 8.6

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2020-3414
High 8.6

A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabil…

cisco ios_xe
0.02EPSS
CVE-2019-1947
High 8.6

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS)…

cisco asyncos · cisco email_security_appliance
0.02EPSS
CVE-2020-3298
High 7.5

A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the reload of an affected devic…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2020-3254
High 7.5

Multiple vulnerabilities in the Media Gateway Control Protocol (MGCP) inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of servic…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · and 10 more
0.02EPSS
CVE-2020-3373
High 8.6

A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. This …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2020-3374
Critical 9.9

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the system configuration, or impact the availabi…

cisco sd-wan
0.02EPSS
CVE-2011-2064
High 7.8

Cisco IOS 12.4MDA before 12.4(24)MDA5 on the Cisco Content Services Gateway - Second Generation (CSG2) allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets, aka Bug ID CSCtl79577.

cisco content_services_gateway_second_generation · cisco ios
0.02EPSS
CVE-2009-1159
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before 7.2(4)26, 8.0 before 8.0(4)22, and 8.1 before 8.1(2)12, when SQL*Net inspection is enabled, allows remote attackers to cause a denial of se…

cisco adaptive_security_appliance_5500 · cisco pix
0.02EPSS
CVE-2009-1158
High 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)26, 8.0 before 8.0(4)24, and 8.1 before 8.1(2)14, when H.323 inspection is enabled, allows remote attackers to c…

cisco adaptive_security_appliance_5500 · cisco pix
0.02EPSS
CVE-2009-0631
High 7.8

Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) all…

cisco ios
0.02EPSS
CVE-2008-3810
High 7.8

Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka CSCsg22426, a different vulnerability than CVE-2008-38…

cisco ios
0.02EPSS
CVE-2008-2056
High 7.8

Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.1.x before 8.1(1)1 allows remote attackers to cause a denial of service (device reload) via a crafted Transport Layer Security (TLS) packet to the device interf…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco pix_security_appliance
0.02EPSS
CVE-2008-1158
High 7.8

The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CSCsh50164.

cisco unified_presence · cisco unified_presence_server
0.02EPSS
CVE-2008-1740
High 7.8

The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via an unspecified "stress test," aka Bug ID CSCsh20972.

cisco unified_presence
0.02EPSS