imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2015-0753
Medium 6.8

SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu30028.

cisco unified_web_and_e-mail_interaction_manager
0.02EPSS
CVE-2018-15405
Medium 6.5

A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to an autho…

cisco ucs_director
0.02EPSS
CVE-2015-0595
Medium 5.0

The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.

cisco webex_meetings_server
0.02EPSS
CVE-2014-3301
Medium 5.0

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.

cisco webex_meetings_server
0.02EPSS
CVE-2013-1185
High 9.3

The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug …

cisco unified_computing_system_6120xp_fabric_interconnect · cisco unified_computing_system_6140xp_fabric_interconnect · cisco unified_computing_system_6248up_fabric_interconnect · cisco unified_computing_system_6296up_fabric_interconnect · and 2 more
0.02EPSS
CVE-2003-1398
High 9.3

Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).

cisco ios
0.02EPSS
CVE-2014-0709
High 9.3

Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obtain administrative access via an SSH session to the CLI interface, aka Bug ID CSCui73930.

cisco ucs_director
0.02EPSS
CVE-2013-1169
High 9.3

Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Remember Me option is used, does not properly verify cookies, which allows remote attackers to impersonate users vi…

cisco unified_meetingplace_web_conferencing_server
0.02EPSS
CVE-2018-15399
Medium 6.8

A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2017-3882
Critical 9.6

A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code ex…

cisco small_business_rv_router_firmware · cisco small_business_rv_router_firmware_1.0
0.02EPSS
CVE-2020-3145
High 8.8

Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute …

cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.02EPSS
CVE-2018-0230
High 8.6

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2009-0621
High 10.0

Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration changes…

cisco ace_4710
0.02EPSS
CVE-2009-0620
High 10.0

Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configur…

cisco application_control_engine_module
0.02EPSS
CVE-2022-20812
Critical 9.0

Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks o…

cisco expressway · cisco telepresence_video_communication_server
0.02EPSS
CVE-2015-6265
Medium 4.3

The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCu…

cisco application_control_engine_4700
0.02EPSS
CVE-2014-2117
Medium 4.3

Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909.

cisco emergency_responder
0.02EPSS
CVE-2014-2116
Medium 4.3

Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.

cisco emergency_responder
0.02EPSS
CVE-2011-3282
High 7.8

Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expi…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2000-0955
High 7.5

Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

cisco virtual_central_office_4000
0.02EPSS
CVE-2016-6420
Medium 6.5

Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.

cisco firesight_system_software
0.02EPSS
CVE-2015-6418
Medium 4.3

The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exc…

cisco rv016_multi-wan_vpn_firmware · cisco rv042_dual_wan_vpn_router_firmware · cisco rv042g_dual_gigabit_wan_vpn_firmware · cisco rv082_dual_wan_vpn_router_firmware · and 3 more
0.02EPSS
CVE-2018-0108
Medium 5.3

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML External Entity (XXE) injection. An attacker could exploit this vulnerability to gain information to conduct additio…

cisco webex_meetings_server
0.02EPSS
CVE-2012-6395
Medium 6.3

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CS…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_1000v_cloud_firewall · cisco asa_5500
0.02EPSS
CVE-2010-1576
High 7.5

The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP he…

cisco ace_4710 · cisco content_services_switch_11500
0.02EPSS