imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2014-0668
Media 4.3

Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949.

cisco secure_access_control_system
0.01EPSS
CVE-2014-0663
Media 4.3

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum03625.

cisco secure_access_control_system
0.01EPSS
CVE-2013-5524
Media 4.3

Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655.

cisco identity_services_engine_software
0.01EPSS
CVE-2013-5504
Media 4.3

Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30266.

cisco identity_services_engine_software
0.01EPSS
CVE-2018-0463
Alta 7.5

A vulnerability in the Cisco Network Plug and Play server component of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to gain unauthorized access to configuration data that is stored on an affected NSO system. The vul…

cisco network_services_orchestrator
0.01EPSS
CVE-2018-0455
Alta 7.5

A vulnerability in the Server Message Block Version 2 (SMBv2) and Version 3 (SMBv3) protocol implementation for the Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the device to run low on system memory, possibly preven…

cisco firepower_system_software
0.01EPSS
CVE-2016-1347
Alta 7.5

The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.

cisco ios
0.01EPSS
CVE-2019-1807
Alta 7.6

A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application n…

cisco umbrella
0.01EPSS
CVE-2018-0187
Media 6.5

A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information.…

cisco identity_services_engine
0.01EPSS
CVE-2021-40117
Alta 8.6

A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5512-x_firmware · e altri 7
0.01EPSS
CVE-2018-0397
Media 5.9

A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthenticated, remote attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. The vulnerability …

cisco advanced_malware_protection_for_endpoints
0.01EPSS
CVE-2013-1223
Alta 7.8

The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub3837…

cisco unified_customer_voice_portal
0.01EPSS
CVE-2010-3033
Alta 9.0

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v…

cisco wireless_lan_controller_software
0.01EPSS
CVE-2010-2843
Alta 9.0

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v…

cisco wireless_lan_controller_software
0.01EPSS
CVE-2010-2842
Alta 9.0

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different v…

cisco wireless_lan_controller_software
0.01EPSS
CVE-2019-1640
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1639
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1638
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1637
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2017-3822
Media 5.3

A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Def…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2018-0462
Media 4.9

A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to insuf…

cisco enterprise_network_virtualization_software
0.01EPSS
CVE-2021-1230
Alta 8.6

A vulnerability with the Border Gateway Protocol (BGP) for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a routing process to crash, which could lead to a denia…

cisco nx-os
0.01EPSS
CVE-2019-16021
Alta 7.5

Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due…

cisco ios_xr
0.01EPSS
CVE-2014-2147
Media 4.3

The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cr…

cisco prime_infrastructure
0.01EPSS
CVE-2015-0599
Media 4.3

The web interface in Cisco Integrated Management Controller in Cisco Unified Computing System (UCS) on C-Series Rack Servers does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspe…

cisco unified_computing_system
0.01EPSS