56.560 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
Vulnerabilità Cisco
6647 CVE
| Identificativo | Gravità, ordinato dal più basso | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-20057 | NONE 0.0 | cisco asyncos A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improp | 0,7% | — |
| CVE-2013-4869 | LOW 0.0 | cisco unified_communications_manager Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' installations, which makes it easier for co | 0,6% | — |
| CVE-1999-1042 | LOW 1.2 | cisco resource_manager Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings. | 0,3% | — |
| CVE-2011-1637 | LOW 1.5 | cisco skinny_client_control_protocol_software Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962. | 0,3% | — |
| CVE-2015-6414 | LOW 2.1 | cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another i | 0,2% | — |
| CVE-2015-6375 | LOW 2.1 | cisco ios The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010. | 0,3% | — |
| CVE-2010-2975 | LOW 2.1 | cisco unified_wireless_network_solution_software Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544. | 0,3% | — |
| CVE-2009-5008 | LOW 2.1 | cisco secure_desktop Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file. | 0,4% | — |
| CVE-2009-4118 | LOW 2.1 | cisco vpn_client The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (servic | 2,5% | — |
| CVE-2007-5549 | LOW 2.1 | cisco ios Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods", aka CSCsk16129. NOTE: as of 20071016, | 0,4% | — |
| CVE-2006-5806 | LOW 2.1 | cisco secure_desktop SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files | 0,3% | — |
| CVE-2006-5394 | LOW 2.1 | cisco secure_desktop The default configuration of Cisco Secure Desktop (CSD) has an unchecked "Disable printing" box in Secure Desktop Settings, which might allow local users to read data that was sent to a printer during another user's SSL VPN session. | 0,3% | — |
| CVE-2006-2166 | LOW 2.1 | cisco unity_express Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any us | 1,6% | — |
| CVE-2005-3427 | LOW 2.1 | cisco ciscoworks_management_center_for_ips_sensors The Cisco Management Center (MC) for IPS Sensors (IPS MC) 2.1 can omit port field values while generating the Cisco IOS IPS configuration file, wich can cause some signatures to be disabled and makes it easier for attackers to escape detection. | 0,4% | — |
| CVE-2005-2451 | LOW 2.1 | cisco ios Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet. | 1,4% | — |
| CVE-2002-0881 | LOW 2.1 | cisco skinny_client_control_protocol_software Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings. | 0,4% | — |
| CVE-2001-1098 | LOW 2.1 | cisco pix_firewall_manager Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file. | 0,5% | — |
| CVE-2001-0741 | LOW 2.1 | cisco hsrp Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets. | 1,3% | — |
| CVE-2001-0444 | LOW 2.1 | cisco cbos Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information. | 0,5% | — |
| CVE-2001-0020 | LOW 2.1 | cisco arrowpoint Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | 0,5% | — |
| CVE-2001-0019 | LOW 2.1 | cisco arrowpoint Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. | 0,3% | — |
| CVE-2000-0368 | LOW 2.1 | cisco ios Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. | 0,4% | — |
| CVE-2000-0345 | LOW 2.1 | cisco ios The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command. | 0,5% | — |
| CVE-1999-1126 | LOW 2.1 | cisco resource_manager Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug. | 0,4% | — |
| CVE-2016-6450 | LOW 2.5 | cisco ios_xe A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system. This vulnerability affects the following products if they are running a | 0,3% | — |