imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2019-12664
Alta 7.5

A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to succe…

cisco ios_xe
0.01EPSS
CVE-2022-20714
Alta 8.6

A vulnerability in the data plane microcode of Lightspeed-Plus line cards for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the line card to reset. This vulnerability is due to the incorrect handlin…

cisco ios_xr
0.01EPSS
CVE-2013-3471
Media 4.3

The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.

cisco identity_services_engine_software
0.01EPSS
CVE-2021-1246
Media 6.5

Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP coul…

cisco finesse
0.01EPSS
CVE-2017-12256
Media 6.5

A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability is due to certain file…

cisco wide_area_application_services
0.01EPSS
CVE-2017-12276
Alta 8.1

A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitra…

cisco prime_collaboration_provisioning
0.01EPSS
CVE-2015-0622
Alta 7.1

The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handled during rendering of the Signature Even…

cisco wireless_lan_controller
0.01EPSS
CVE-2020-3285
Media 5.8

A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffi…

cisco secure_firewall_threat_defense
0.01EPSS
CVE-1999-0734
Alta 7.5

A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

cisco ciscosecure
0.01EPSS
CVE-2017-6674
Alta 7.5

A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. More Information: CSCvb16413. Known Affec…

cisco firesight_system
0.01EPSS
CVE-2016-1485
Media 6.1

Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497.

cisco identity_services_engine_software
0.01EPSS
CVE-2016-1447
Media 6.1

Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuy83194.

cisco webex_meetings_server
0.01EPSS
CVE-2015-6285
Media 6.4

Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.

cisco email_security_appliance
0.01EPSS
CVE-2002-1103
Media 5.0

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client
0.01EPSS
CVE-2016-1437
Media 6.5

SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.

cisco prime_collaboration_deployment
0.01EPSS
CVE-2020-3563
Alta 8.6

A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to inefficient …

cisco secure_firewall_threat_defense
0.01EPSS
CVE-2020-3560
Alta 8.6

A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device. The vulnerability is due to improper resource management while processing specific packets. An attack…

cisco access_points · cisco aironet_access_point_software · cisco business_access_points · cisco wireless_lan_controller · e altri 1
0.01EPSS
CVE-2020-3509
Alta 8.6

A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (DoS) condition. The vu…

cisco ios_xe
0.01EPSS
CVE-2020-3369
Alta 7.5

A vulnerability in the deep packet inspection (DPI) engine of Cisco SD-WAN vEdge Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of FTP …

cisco sd-wan_firmware · cisco vedge_cloud_router
0.01EPSS
CVE-2019-15262
Alta 7.5

A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because t…

cisco 5508_wireless_lan_controller_firmware · cisco 5520_wireless_lan_controller_firmware
0.01EPSS
CVE-2018-15391
Alta 7.5

A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is…

cisco remote
0.01EPSS
CVE-1999-0453
Media 5.0

An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).

cisco router
0.01EPSS
CVE-2022-20720
Media 5.5

Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system…

cisco ios_xe
0.01EPSS
CVE-2019-1955
Alta 7.5

A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to …

cisco email_security_appliance_firmware
0.01EPSS
CVE-2019-1921
Media 5.8

A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validat…

cisco email_security_appliance
0.01EPSS