imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2015-6317
Media 6.5

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

cisco identity_services_engine_software
0.01EPSS
CVE-2017-3817
Media 4.3

A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CSCvc32…

cisco unified_computing_system_director
0.01EPSS
CVE-2020-3112
Alta 8.8

A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privileges on the application. The vulnerability is due to insufficient access control validation. An attacker could e…

cisco data_center_network_manager
0.01EPSS
CVE-2019-1929
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1928
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1925
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2017-3880
Media 6.5

An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 C…

cisco webex_meetings_server
0.01EPSS
CVE-2021-1378
Media 5.3

A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logi…

cisco staros
0.01EPSS
CVE-2019-1657
Media 4.3

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain …

cisco amp_threat_grid_appliance · cisco amp_threat_grid_cloud
0.01EPSS
CVE-2017-6673
Media 6.5

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.…

cisco secure_firewall_management_center
0.01EPSS
CVE-2016-6394
Critica 9.1

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.

cisco firesight_system_software
0.01EPSS
CVE-2013-6974
Media 4.3

Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud89431.

cisco secure_access_control_system
0.01EPSS
CVE-2015-6361
Media 6.5

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

cisco dpc3939_wireless_residential_voice_gateway_firmware
0.01EPSS
CVE-2013-5474
Alta 7.8

Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud6481…

cisco ios
0.01EPSS
CVE-2005-1057
Alta 7.5

Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."

cisco ios
0.01EPSS
CVE-2005-1058
Alta 7.5

Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and m…

cisco ios
0.01EPSS
CVE-2019-1946
Media 6.5

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management interface. The vulnerabili…

cisco enterprise_network_function_virtualization_infrastructure
0.01EPSS
CVE-2018-0110
Alta 8.1

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco WebEx Meetings Server,…

cisco webex_meetings_server
0.01EPSS
CVE-2021-1263
Alta 7.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.01EPSS
CVE-2022-20791
Media 6.5

A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified …

cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service
0.01EPSS
CVE-2022-20683
Alta 8.6

A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected…

cisco ios_xe
0.01EPSS
CVE-2019-1877
Media 6.5

A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download functio…

cisco enterprise_chat_and_email
0.01EPSS
CVE-2015-0700
Media 6.8

Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solution Engine before 5.5(0.46.5) allows remote attackers to hijack the authentication of arbitrary users, aka Bug…

cisco secure_access_control_server_solution_engine
0.01EPSS
CVE-2018-0134
Media 5.3

A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component retur…

cisco mobility_services_engine
0.01EPSS
CVE-2014-0665
Media 4.0

The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaini…

cisco identity_services_engine_software
0.01EPSS