imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2019-1820
Media 6.5

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.14EPSS
CVE-2019-1819
Media 6.5

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.14EPSS
CVE-2019-1818
Media 6.5

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files within the application that should be res…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.14EPSS
CVE-2006-3109
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phoneli…

cisco call_manager
0.14EPSS
CVE-2018-0476
Media 5.9

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due …

cisco ios_xe
0.14EPSS
CVE-2021-34730
Critica 9.8

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resul…

cisco application_extension_platform · cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_wireless-n_multifunction_vpn_router_firmware · e altri 1
0.14EPSS
CVE-2006-0179
Media 5.0

The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.

cisco ip_phone_7940
0.14EPSS
CVE-2013-2683
Media 5.3

Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.

cisco linksys_e4200_firmware
0.13EPSS
CVE-2025-20284
Media 6.5

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input.…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.13EPSS
CVE-2007-4430
Media 5.0

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated re…

cisco cbos · cisco cli · cisco ids · cisco ios · e altri 1
0.13EPSS
CVE-2020-3387
Alta 8.8

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to execute code with root privileges on an affected system. The vulnerability is due to insufficient input sanitization during user authentication processing. An att…

cisco sd-wan_firmware
0.13EPSS
CVE-2006-4098
Alta 10.0

Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.

cisco secure_access_control_server
0.13EPSS
CVE-2017-12373
Media 5.9

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (R…

cisco adaptive_security_appliance_5505_firmware · cisco adaptive_security_appliance_5510_firmware · cisco adaptive_security_appliance_5520_firmware · cisco adaptive_security_appliance_5540_firmware · e altri 1
0.13EPSS
CVE-2011-2577
Alta 7.8

Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP packet to…

cisco telepresence_6000_mxp · cisco telepresence_9000_mxp · cisco telepresence_c_series_software · cisco telepresence_codec_c40 · e altri 7
0.13EPSS
CVE-2023-20036
Critica 9.9

A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This vulnerability is due to improper input valid…

cisco industrial_network_director
0.13EPSS
CVE-2009-1161
Alta 10.0

Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, …

cisco ciscoworks_common_services · cisco ciscoworks_health_and_utilization_monitor · cisco ciscoworks_lan_management_solution · cisco ciscoworks_qos_policy_manager · e altri 6
0.13EPSS
CVE-2022-20624
Alta 8.6

A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validati…

cisco nx-os
0.12EPSS
CVE-2001-0041
Alta 7.8

Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.

cisco catos
0.12EPSS
CVE-2020-26073
Alta 7.5

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character s…

cisco catalyst_sd-wan_manager
0.12EPSS
CVE-2022-20623
Alta 8.6

A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This…

cisco nx-os
0.12EPSS
CVE-2006-4313
Media 5.0

Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or crea…

cisco vpn_3000_concentrator_series_software
0.12EPSS
CVE-2006-3733
Alta 7.5

jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute …

cisco security_monitoring_analysis_and_response_system
0.12EPSS
CVE-2026-20147
Critica 9.9

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative cred…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.12EPSS
CVE-2008-7257
Media 4.3

CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a …

cisco asa_5580
0.12EPSS
CVE-2011-2543
Alta 9.0

Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long location p…

cisco telepresence_c_series_software · cisco telepresence_codec_c40 · cisco telepresence_codec_c60 · cisco telepresence_codec_c90
0.12EPSS