imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2018-0283
Media 5.8

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The v…

cisco secure_firewall_management_center
0.01EPSS
CVE-2018-0281
Media 5.8

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of the Snort detection engine on an affected device, resulting in a brief denial of service (DoS) condition. The v…

cisco secure_firewall_management_center
0.01EPSS
CVE-2001-0429
Media 5.0

Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.

cisco catos
0.01EPSS
CVE-2020-26078
Media 6.5

A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attacker could exploit thi…

cisco iot_field_network_director
0.01EPSS
CVE-2020-3262
Alta 7.5

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol handler of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devi…

cisco 5508_wireless_controller_firmware · cisco 5520_wireless_controller_firmware
0.01EPSS
CVE-2022-20756
Alta 8.6

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS reque…

cisco identity_services_engine
0.01EPSS
CVE-2021-1377
Media 5.8

A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subne…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2020-3528
Alta 8.6

A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2007-1800
Alta 7.5

Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might b…

cisco trust_agent
0.01EPSS
CVE-2021-34698
Alta 8.6

A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected device. This vulnerability is due…

cisco asyncos
0.01EPSS
CVE-2021-1532
Media 6.5

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability…

cisco roomos · cisco telepresence_collaboration_endpoint
0.01EPSS
CVE-2017-3811
Media 6.5

An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fi…

cisco webex_meetings_server
0.01EPSS
CVE-2019-1641
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2016-1315
Alta 7.5

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded…

cisco email_security_appliance_firmeware
0.01EPSS
CVE-2020-27132
Critica 9.9

Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive informati…

cisco jabber · cisco jabber_for_mobile_platforms
0.01EPSS
CVE-2018-15424
Media 4.7

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web se…

cisco identity_services_engine
0.01EPSS
CVE-2021-1261
Alta 7.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.01EPSS
CVE-2021-1260
Alta 7.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.01EPSS
CVE-2013-3436
Media 5.0

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain …

cisco ios
0.01EPSS
CVE-2014-0681
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of repo…

cisco identity_services_engine_software
0.01EPSS
CVE-2013-1111
Alta 9.0

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka …

cisco ata_187_analog_telephone_adaptor · cisco ata_187_analog_telephone_adaptor_firmware
0.01EPSS
CVE-2022-20745
Alta 8.6

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2015-0610
Media 4.3

Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express For…

cisco ios
0.01EPSS
CVE-2014-0678
Media 5.5

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951.

cisco secure_access_control_system
0.01EPSS
CVE-2020-3597
Media 5.4

A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of confi…

cisco nexus_data_broker
0.01EPSS