imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2010-0588
Alta 7.8

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdSt…

cisco unified_communications_manager
0.02EPSS
CVE-2014-3384
Alta 7.8

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creatio…

cisco asa
0.02EPSS
CVE-2014-2161
Alta 7.8

The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45731.

cisco tandberg_2000_mxp · cisco tandberg_550_mxp · cisco tandberg_770_mxp · cisco tandberg_880_mxp · e altri 9
0.02EPSS
CVE-2014-2160
Alta 7.8

The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45745.

cisco tandberg_2000_mxp · cisco tandberg_550_mxp · cisco tandberg_770_mxp · cisco tandberg_880_mxp · e altri 9
0.02EPSS
CVE-2014-2159
Alta 7.8

The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCtq78722.

cisco tandberg_2000_mxp · cisco tandberg_550_mxp · cisco tandberg_770_mxp · cisco tandberg_880_mxp · e altri 9
0.02EPSS
CVE-2014-0719
Alta 7.8

The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (MainApp process outage) via crafted packets to TCP port 7000, aka Bug ID CSCui67394.

cisco ips_sensor_software
0.02EPSS
CVE-2010-0147
Media 6.5

SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

cisco security_agent
0.02EPSS
CVE-2003-0677
Media 5.0

Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure."

cisco webns
0.02EPSS
CVE-2021-1415
Media 6.3

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2021-1413
Media 6.3

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2020-3365
Media 4.3

A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories. The vulnerability is due to a…

cisco enterprise_network_function_virtualization_infrastructure
0.02EPSS
CVE-2002-1553
Alta 7.5

Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.

cisco optical_networking_systems_software
0.02EPSS
CVE-2002-1190
Alta 7.5

Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

cisco unity_server
0.02EPSS
CVE-2002-0778
Alta 7.5

The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.

cisco cache_engine_505 · cisco cache_engine_550 · cisco cache_engine_570 · cisco content_distribution_manager_4630 · e altri 4
0.02EPSS
CVE-2001-0455
Alta 7.5

Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.

cisco aironet_340
0.02EPSS
CVE-2018-0256
Media 5.8

A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote attacker to cause the Session Manager (SESSMGR) process on an affected device to restart, resulting in a denial of …

cisco asr_5000_series_software
0.02EPSS
CVE-2017-12278
Media 6.3

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerabili…

cisco wireless_lan_controller_software
0.02EPSS
CVE-2017-6757
Alta 8.8

A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplie…

cisco unified_communications_manager
0.02EPSS
CVE-2021-1132
Media 5.3

A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management interface…

cisco network_services_orchestrator
0.02EPSS
CVE-2022-20767
Alta 8.6

A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper hand…

cisco secure_firewall_threat_defense
0.02EPSS
CVE-2012-4099
Media 4.3

The BGP implementation in Cisco NX-OS does not properly filter AS paths, which allows remote attackers to cause a denial of service (BGP service reset and resync) via a malformed UPDATE message, aka Bug ID CSCtn13065.

cisco nx-os
0.02EPSS
CVE-2007-2587
Media 6.3

The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).

cisco ios
0.02EPSS
CVE-2019-15972
Alta 8.8

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interf…

cisco unified_communications_manager
0.02EPSS
CVE-2018-0394
Alta 8.8

A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted shell access on an affected system. The vulnerability is due to insufficient input validation of parameters pass…

cisco cloud_services_platform_2100
0.02EPSS
CVE-2024-20272
Alta 7.3

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due t…

cisco unity_connection
0.02EPSS