imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2017-6710
High 8.1

A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server. The vulnerability is due to command settings that al…

cisco virtual_network_function_element_manager
0.02EPSS
CVE-2015-4202
Medium 5.0

Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information …

cisco ios
0.02EPSS
CVE-2014-2153
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869.

cisco prime_infrastructure
0.02EPSS
CVE-2022-20842
Critical 9.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information ab…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2014-2114
Medium 4.3

Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384.

cisco emergency_responder
0.02EPSS
CVE-2014-2118
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in dashboard-related HTML documents in Cisco Prime Security Manager (aka PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun5…

cisco prime_security_manager
0.02EPSS
CVE-2014-3316
Medium 4.0

The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.

cisco unified_communications_manager
0.02EPSS
CVE-2014-0732
Medium 5.0

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to…

cisco unified_communications_manager
0.02EPSS
CVE-2020-3425
High 8.8

Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information ab…

cisco ios_xe
0.02EPSS
CVE-2011-3280
High 7.5

Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug …

cisco ios · cisco ios_xe
0.02EPSS
CVE-2020-3228
High 8.6

A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) …

cisco ios · cisco ios_xe · cisco nx-os
0.02EPSS
CVE-2011-4005
High 9.3

Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546W, and SRP547W with f…

cisco small_business_srp520_series_firmware · cisco small_business_srp521w · cisco small_business_srp526w · cisco small_business_srp527w · and 4 more
0.02EPSS
CVE-2011-0963
Medium 5.0

The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified v…

cisco nac_guest_server · cisco nac_guest_server_software
0.02EPSS
CVE-2012-2469
High 7.8

Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) policy is configured for Reset, allows remote attackers to cause a denial of service (device reset) via a malformed Cisco Discovery Protocol (CDP) packet, aka Bug…

cisco nexus_7000 · cisco nexus_7000_10-slot · cisco nexus_7000_18-slot · cisco nexus_7000_9-slot · and 1 more
0.02EPSS
CVE-2013-1205
Medium 4.3

The Event Center module in Cisco WebEx Meetings Server does not perform request authentication in all intended circumstances, which allows remote attackers to discover host keys and event passwords via crafted URLs, aka Bug ID CSCue62485.

cisco webex_meetings_server
0.02EPSS
CVE-2019-1696
High 7.5

Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition. For mo…

cisco secure_firewall_management_center · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2018-0242
Medium 6.1

A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2016-9214
Medium 6.1

Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvb86332 CSCvb86…

cisco identity_services_engine_software
0.02EPSS
CVE-2016-9206
Medium 6.1

A vulnerability in the ccmadmin page of Cisco Unified Communications Manager (CUCM) could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvb64641. Known Affected Releases: 11.5(1.10000.6) …

cisco unified_communications_manager
0.02EPSS
CVE-2016-9200
Medium 6.1

A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface. More Information: CSCut43268. Known Affected …

cisco prime_collaboration_assurance
0.02EPSS
CVE-2012-4660
High 7.8

The SIP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.17), 8.3 before 8.3(2.28), 8.4 before 8.4(2.13), 8.5 before 8.5…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco catalyst_6500 · cisco catalyst_6503-e · and 7 more
0.02EPSS
CVE-2012-4619
High 7.8

The NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtr46123.

cisco ios
0.02EPSS
CVE-2012-3073
High 7.8

The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process cras…

cisco telepresence_manager · cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software · cisco telepresence_recording_server · and 11 more
0.02EPSS
CVE-2011-3295
High 7.8

The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.

cisco ios_xr
0.02EPSS
CVE-2011-3281
High 7.8

Unspecified vulnerability in Cisco IOS 15.0 through 15.1, in certain HTTP Layer 7 Application Control and Inspection configurations, allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTP packet, aka Bug ID CSCto68554.

cisco ios
0.02EPSS