imPC@ndo IT

Cisco vulnerabilities

6641 CVE

CVE-2004-1458
Medium 5.0

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.

cisco secure_access_control_server · cisco secure_acs_solution_engine
0.02EPSS
CVE-2018-0326
Medium 6.1

A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against a user of the web UI of the affected software. The vulnerability is due to insufficient …

cisco telepresence_tx9000_firmware
0.02EPSS
CVE-2016-1427
High 7.5

The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages, aka Bug ID CSCuv35694.

cisco prime_network_registrar
0.02EPSS
CVE-2020-3255
High 7.5

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient …

cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · and 9 more
0.02EPSS
CVE-2020-3189
High 8.6

A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behavio…

cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · and 9 more
0.02EPSS
CVE-2014-0733
Medium 5.0

The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bu…

cisco unified_communications_manager
0.02EPSS
CVE-2012-1367
Medium 5.0

The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSC…

cisco ios
0.02EPSS
CVE-2010-2978
High 10.0

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended access restrictions via vectors involving collisions, aka Bug ID…

cisco unified_wireless_network_solution_software
0.02EPSS
CVE-2021-1480
High 7.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2014-3304
Medium 5.0

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722.

cisco webex_meetings_server
0.02EPSS
CVE-2013-3469
Medium 5.0

Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug I…

cisco mobility_services_engine
0.02EPSS
CVE-2020-3443
High 8.8

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and execute commands with higher privileges. The vulnerability is due to insufficient authorization of the System Operator…

cisco smart_software_manager_on-prem
0.02EPSS
CVE-2015-0594
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified param…

cisco prime_lan_management_solution · cisco security_manager
0.02EPSS
CVE-2014-3365
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo9…

cisco prime_security_manager
0.02EPSS
CVE-2014-8021
Medium 4.3

Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving an applet-path UR…

cisco anyconnect_secure_mobility_client · cisco hostscan_engine
0.02EPSS
CVE-2014-8022
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and CSCur69776.

cisco identity_services_engine_software
0.02EPSS
CVE-2014-8026
Medium 4.3

Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074.

cisco jabber_guest
0.02EPSS
CVE-2014-3378
Medium 5.0

tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468.

cisco ios_xr
0.02EPSS
CVE-2014-0735
Medium 4.3

Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum464…

cisco unified_communications_manager
0.02EPSS
CVE-2013-6962
Medium 4.3

Cross-site scripting (XSS) vulnerability in the mobile-browser subsystem in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36228.

cisco webex_meeting_center
0.02EPSS
CVE-2013-6961
Medium 4.3

Cross-site scripting (XSS) vulnerability in the Collaboration Partner Access Console (CPAC) in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36237.

cisco webex_meeting_center
0.02EPSS
CVE-2013-5483
Medium 4.3

Cross-site scripting (XSS) vulnerability in bookmarklet.jsp in Cisco SocialMiner allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuh73868.

cisco socialminer
0.02EPSS
CVE-2013-3439
Medium 4.3

Cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a crafted URL in an unspecified HTTP header field, aka Bug ID CSCud80182.

cisco unified_operations_manager
0.02EPSS
CVE-2016-6461
Medium 5.9

A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to inject arbitrary XML commands on the affected system. More Information: CSCva38556. Known Affected Rele…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2018-0459
Medium 6.5

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side…

cisco network_functions_virtualization_infrastructure
0.02EPSS