imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2013-1164
High 7.8

Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via…

cisco asr_1001 · cisco asr_1002 · cisco asr_1002-x · cisco asr_1004 · and 3 more
0.02EPSS
CVE-2019-1900
High 7.5

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to cause the web server process to crash, causing a denial of service (DoS) condition on an affected system. The vulnerability is …

cisco integrated_management_controller_supervisor · cisco unified_computing_system
0.02EPSS
CVE-2013-5553
High 7.8

Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.

cisco ios
0.02EPSS
CVE-2013-3388
High 7.8

Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776.

cisco prime_central_for_hosted_collaboration_solution_assurance
0.02EPSS
CVE-2013-3382
High 7.8

The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (device reload or traffi…

cisco adaptive_security_appliance
0.02EPSS
CVE-2008-0527
High 7.8

The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.

cisco session_initiation_protocol_\(sip\)_firmware · cisco skinny_client_control_protocol_\(sccp\)_firmware
0.02EPSS
CVE-2014-0731
Medium 5.0

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.

cisco unified_communications_manager
0.02EPSS
CVE-2011-1643
High 10.0

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Presence Server 6.x, 7.x, 8.0, and 8.5 before 8.5xnr allow remote attackers to read database data by connecting to…

cisco unified_communications_manager · cisco unified_presence_server
0.02EPSS
CVE-2021-1247
High 8.8

Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the …

cisco data_center_network_manager
0.02EPSS
CVE-2020-26070
High 8.6

A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vu…

cisco ios_xr
0.02EPSS
CVE-2019-1825
High 8.1

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the s…

cisco evolved_programmable_network_manager · cisco network_level_service · cisco prime_infrastructure
0.02EPSS
CVE-2019-1824
High 8.1

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the s…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.02EPSS
CVE-2015-0722
High 7.8

The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.

cisco telepresence_tc_software · cisco telepresence_te_software
0.02EPSS
CVE-2013-5566
Medium 5.0

Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.

cisco nx-os
0.02EPSS
CVE-2011-1646
High 9.0

The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N Gigabit Security Router with software before 2.0.2.1, allows remote authenticated users to execute arbitrary co…

cisco rvs4000 · cisco rvs4000_software · cisco wrvs4400n · cisco wrvs4400n_software
0.02EPSS
CVE-2018-0333
Medium 5.8

A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic configuration changes that could allow an attacker to bypass…

cisco secure_firewall_management_center
0.02EPSS
CVE-2017-6612
High 8.6

A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSC…

cisco asr_5000_series_software
0.02EPSS
CVE-2003-0216
High 9.3

Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

cisco catos
0.02EPSS
CVE-2018-0460
Medium 6.5

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks…

cisco network_functions_virtualization_infrastructure
0.02EPSS
CVE-2017-3796
High 7.2

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6.

cisco webex_meetings_server
0.02EPSS
CVE-2015-0685
High 7.8

Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.

cisco ios_xe
0.02EPSS
CVE-2015-0652
High 7.8

The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled excepti…

cisco expressway_software · cisco telepresence_conductor · cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2012-3946
Medium 5.0

Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bu…

cisco ios
0.02EPSS
CVE-2013-3386
High 7.8

The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102 and 8.0 b…

cisco ironport_asyncos
0.02EPSS
CVE-2012-3079
High 7.8

Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.

cisco ios
0.02EPSS