imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2014-3349
Media 4.0

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to upload arbitrary files via a crafted request, aka Bug ID CSCuh87410.

cisco cloud_portal
0.02EPSS
CVE-2014-2145
Media 4.0

Directory traversal vulnerability in the messaging API in Cisco Unity Connection allows remote authenticated users to read arbitrary files via vectors related to unenforced access constraints for .wav files and the audio/x-wav MIME type, aka Bug ID CSCun91071.…

cisco unity_connection
0.02EPSS
CVE-2001-0862
Alta 7.5

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.

cisco 12000_router
0.02EPSS
CVE-2013-5513
Alta 7.1

Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.3), and 9.1.x before 9.1(1.8), when the DNS ALPI eng…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2005-0943
Media 5.0

Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client · cisco vpn_3005_concentrator_software · cisco vpn_3015_concentrator · e altri 4
0.02EPSS
CVE-2013-1168
Alta 7.6

The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack session…

cisco unified_meetingplace
0.02EPSS
CVE-2022-20799
Media 4.7

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Thes…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2016-1406
Alta 8.8

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.02EPSS
CVE-2015-6407
Media 4.0

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

cisco emergency_responder
0.02EPSS
CVE-2009-1165
Alta 7.8

Memory leak on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0, 5.1 before 5.1.163.0, and 5.0 and 5.2 before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Mo…

cisco catalyst_3750g · cisco cisco_1500_wireless_lan_controller · cisco cisco_2000_wireless_lan_controller · cisco cisco_2100_wireless_lan_controller · e altri 3
0.02EPSS
CVE-2009-1163
Alta 7.8

Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets.

cisco physical_access_gateway
0.02EPSS
CVE-2009-0061
Alta 7.8

Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.…

cisco 4400_wireless_lan_controller · cisco catalyst_3750_series_integrated_wireless_lan_controller · cisco catalyst_6500_series_integrated_wireless_lan_controller · cisco catalyst_7600_series_wireless_lan_controller · e altri 1
0.02EPSS
CVE-2007-0963
Alta 7.8

Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as …

cisco firewall_services_module
0.02EPSS
CVE-2002-0241
Alta 7.5

NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.

cisco secure_access_control_server
0.02EPSS
CVE-2020-3500
Media 6.8

A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An atta…

cisco staros
0.02EPSS
CVE-2016-1364
Alta 7.5

Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908.

cisco wireless_lan_controller_software
0.02EPSS
CVE-2013-6964
Bassa 3.5

Cisco WebEx Meeting Center allows remote authenticated users to bypass access control and inject content from a different WebEx site via unspecified vectors, aka Bug ID CSCul36197.

cisco webex_meeting_center
0.02EPSS
CVE-2021-34739
Alta 8.1

A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface o…

cisco cbs250-16p-2g_firmware · cisco cbs250-16t-2g_firmware · cisco cbs250-24fp-4g_firmware · cisco cbs250-24fp-4x_firmware · e altri 205
0.02EPSS
CVE-2021-1304
Alta 8.8

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and …

cisco catalyst_sd-wan_manager
0.02EPSS
CVE-2006-2166
Bassa 2.1

Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any us…

cisco unity_express · cisco unity_express_software
0.02EPSS
CVE-2002-1093
Media 5.0

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

cisco vpn_3000_concentrator_series_software
0.02EPSS
CVE-2002-1102
Media 5.0

The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote netw…

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client
0.02EPSS
CVE-2002-1104
Media 5.0

Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

cisco vpn_client
0.02EPSS
CVE-2010-0585
Alta 7.8

Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control…

cisco ios
0.02EPSS
CVE-2010-0591
Alta 7.8

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow…

cisco unified_communications_manager
0.02EPSS