imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2022-20866
Alta 7.4

A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.17EPSS
CVE-2019-1912
Critica 9.1

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management inter…

cisco sf-220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · e altri 7
0.17EPSS
CVE-2013-2678
Alta 8.1

Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type pa…

cisco linksys_e4200_firmware
0.17EPSS
CVE-2025-20125
Critica 9.1

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in …

cisco identity_services_engine
0.17EPSS
CVE-2003-0567
Alta 7.8

Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.

cisco ios · cisco ons_15454_optical_transport_platform · cisco optical_networking_systems_software
0.17EPSS
CVE-2018-0472
Alta 8.6

A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to im…

cisco ios_xe
0.16EPSS
CVE-2018-15442
Alta 7.8

A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied paramete…

cisco webex_meetings_desktop · cisco webex_productivity_tools
0.16EPSS
CVE-2023-20048
Critica 9.9

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by…

cisco secure_firewall_management_center
0.16EPSS
CVE-2023-20238
Critica 10.0

A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected …

cisco broadworks_application_delivery_platform · cisco broadworks_xtended_services_platform
0.15EPSS
CVE-2020-12695
Alta 7.5

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

asus rt-n11 · broadcom adsl · canon selphy_cp1200 · canonical ubuntu_linux · e altri 213
0.15EPSS
CVE-2011-3310
Alta 9.0

The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoW…

cisco ciscoworks_common_services · microsoft windows
0.15EPSS
CVE-2017-17428
Media 5.9

Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

cavium nitrox_ssl_sdk · cavium nitrox_v_ssl_sdk · cavium octeon_sdk · cavium octeon_ssl_sdk · e altri 10
0.15EPSS
CVE-2025-20265
Critica 10.0

A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device.  This vulnerability is …

cisco secure_firewall_management_center
0.15EPSS
CVE-2017-3807
Alta 8.8

A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient va…

cisco adaptive_security_appliance_software
0.15EPSS
CVE-2007-5381
Alta 9.3

Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be print…

cisco ios
0.15EPSS
CVE-2011-0951
Media 5.0

The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.

cisco secure_access_control_system
0.15EPSS
CVE-2022-20650
Alta 8.8

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the …

cisco nx-os
0.15EPSS
CVE-2007-2586
Alta 9.3

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves ac…

cisco ios
0.14EPSS
CVE-2021-1388
Critica 10.0

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper toke…

cisco aci_multi-site_orchestrator · cisco application_policy_infrastructure_controller
0.14EPSS
CVE-2019-15982
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit…

cisco data_center_network_manager
0.14EPSS
CVE-2019-15981
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit…

cisco data_center_network_manager
0.14EPSS
CVE-2019-1599
Alta 8.6

A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in…

cisco nx-os
0.14EPSS
CVE-2005-2841
Alta 7.5

Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authen…

cisco ios
0.14EPSS
CVE-2007-4459
Alta 7.1

Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain inval…

cisco voip_phone_cp-7940 · cisco voip_phone_cp-7960
0.14EPSS
CVE-2011-0354
Alta 10.0

The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified l…

cisco tandberg_endpoint · cisco tandberg_personal_video_unit · cisco tandberg_personal_video_unit_software
0.14EPSS