imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2019-1680
Media 4.3

A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerability by convincing a…

cisco webex_business_suite · cisco webex_meetings_online
0.01EPSS
CVE-2016-6474
Alta 7.3

A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on an affected system. More Information: CSCuv89417. Known A…

cisco ios
0.01EPSS
CVE-2009-2976
Alta 7.8

Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to discover Wireless LAN Controller MAC addresses and IP addresses, and AP configuration details, by sniffing the…

cisco aironet_ap1100 · cisco aironet_ap1200
0.01EPSS
CVE-2021-1349
Media 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerability is due to insufficient input valida…

cisco sd-wan_vmanage
0.01EPSS
CVE-2021-1144
Alta 8.8

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of authorization …

cisco connected_mobile_experiences
0.01EPSS
CVE-2005-2451
Bassa 2.1

Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.

cisco ios · cisco ios_xr
0.01EPSS
CVE-2015-6290
Media 4.3

Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.

cisco web_security_virtual_appliance
0.01EPSS
CVE-2014-0667
Media 6.3

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169.

cisco secure_access_control_system
0.01EPSS
CVE-2021-1303
Alta 8.8

A vulnerability in the user management roles of Cisco DNA Center could allow an authenticated, remote attacker to execute unauthorized commands on an affected device. The vulnerability is due to improper enforcement of actions for assigned user roles. An attac…

cisco catalyst_center
0.01EPSS
CVE-2020-3559
Alta 8.6

A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper handling of clients that are trying to connect to the AP. An attacker could …

cisco access_points · cisco aironet_access_point_software · cisco business_access_points · cisco wireless_lan_controller
0.01EPSS
CVE-2019-15286
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-15284
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validatio…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2020-3480
Alta 8.6

Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handli…

cisco ios_xe
0.01EPSS
CVE-2012-2495
Media 4.3

The HostScan downloader implementation in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR8 and Cisco Secure Desktop before 3.6.6020 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attacke…

cisco anyconnect_secure_mobility_client · cisco secure_desktop
0.01EPSS
CVE-2012-2494
Media 4.3

The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 and 3.x before 3.0 MR8 does not compare the timestamp of offered software to the timestamp of installed software, which allows remote attac…

cisco anyconnect_secure_mobility_client
0.01EPSS
CVE-2011-0396
Alta 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary file…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500 · cisco asa_5505 · e altri 13
0.01EPSS
CVE-2020-3321
Bassa 3.3

A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnera…

cisco webex_network_recording_player · cisco webex_player
0.01EPSS
CVE-2016-6446
Alta 7.5

A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.

cisco meeting_server
0.01EPSS
CVE-2016-6410
Media 6.5

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.

cisco ios
0.01EPSS
CVE-2019-15258
Media 6.5

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper valid…

cisco spa112_firmware · cisco spa122_firmware
0.01EPSS
CVE-2016-1345
Alta 7.5

Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.

cisco asa_with_firepower_services · cisco firesight_system_software
0.01EPSS
CVE-2021-1594
Alta 7.5

A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specifi…

cisco identity_services_engine
0.01EPSS
CVE-2008-3819
Media 5.0

dnsserver in Cisco Application Control Engine Global Site Selector (GSS) before 3.0(1) allows remote attackers to cause a denial of service (daemon crash) via a series of crafted DNS requests, aka Bug ID CSCsj70093.

cisco gss_4480_global_site_selector · cisco gss_4490_global_site_selector · cisco gss_4491_global_site_selector · cisco gss_4492r_global_site_selector
0.01EPSS
CVE-1999-1001
Bassa 2.6

Cisco Cache Engine allows a remote attacker to gain access via a null username and password.

cisco cache_engine
0.01EPSS
CVE-2018-0120
Media 4.3

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerability exists because the affected software fails to validate u…

cisco unified_communications_manager
0.01EPSS