imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2013-1210
Media 5.4

Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of service (ESXi crash and purple screen of death) by sending craf…

cisco nx-os
0.02EPSS
CVE-2023-20076
Alta 7.2

A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters tha…

cisco 807_industrial_integrated_services_router_firmware · cisco 809_industrial_integrated_services_router_firmware · cisco 829_industrial_integrated_services_router_firmware · cisco cgr1000_firmware · e altri 5
0.02EPSS
CVE-2012-5017
Media 6.8

Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.

cisco asr_1001 · cisco asr_1002 · cisco asr_1002-x · cisco asr_1002_fixed_router · e altri 4
0.02EPSS
CVE-2013-1217
Media 6.8

The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests at the same time, aka Bug ID CSCub41105.

cisco ios
0.02EPSS
CVE-2002-1099
Media 5.0

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client
0.02EPSS
CVE-2004-1112
Media 5.1

The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer ove…

cisco security_agent · okena stormwatch
0.02EPSS
CVE-2018-0218
Bassa 3.3

A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improp…

cisco secure_access_control_server_solution_engine
0.02EPSS
CVE-2012-0388
Alta 7.8

Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553…

cisco ios
0.02EPSS
CVE-2018-0461
Media 6.5

A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insuff…

cisco ip_phone_8800_series_firmware
0.02EPSS
CVE-2020-3150
Media 5.9

A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which could include the device configuration. The …

cisco rv110w_firmware · cisco rv215w_firmware
0.01EPSS
CVE-2016-6422
Alta 7.5

Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM share ACLs, which allows remote attackers to bypass intended access restrictions by sending packets that should h…

cisco ios
0.01EPSS
CVE-2012-1342
Media 5.8

Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

cisco carrier_routing_system
0.01EPSS
CVE-2017-6689
Alta 8.8

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc7666…

cisco elastic_services_controller
0.01EPSS
CVE-2017-6687
Alta 8.8

A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Pass…

cisco ultra_services_framework_element_manager
0.01EPSS
CVE-2017-6686
Alta 8.8

A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. …

cisco ultra_services_framework_element_manager
0.01EPSS
CVE-2017-6685
Alta 8.8

A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More Info…

cisco ultra_services_framework_staging_server
0.01EPSS
CVE-2015-4263
Media 4.0

The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.

cisco mobility_services_engine
0.01EPSS
CVE-2014-8010
Media 6.5

The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.

cisco unified_communications_domain_manager
0.01EPSS
CVE-2008-1743
Alta 7.8

Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a ser…

cisco unified_communications_manager
0.01EPSS
CVE-2002-0870
Alta 7.5

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of …

cisco content_services_switch_11000 · cisco webns
0.01EPSS
CVE-2015-0598
Media 6.8

The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted IPv6 Attributes in Access-Accept packets, aka Bug IDs CSCur84322 and CSCur27693.

cisco ios · cisco ios_xe
0.01EPSS
CVE-2014-3269
Media 6.8

The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

cisco ios_xe
0.01EPSS
CVE-2013-6686
Media 6.8

The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.

cisco ios
0.01EPSS
CVE-2015-0671
Media 5.0

The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911.

cisco videoscape_delivery_system_for_internet_streamer
0.01EPSS
CVE-2013-5536
Media 5.0

Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) via a flood of crafted packets, aka Bug ID CSCui51521.

cisco secure_access_control_system
0.01EPSS