imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2013-5489
Media 5.0

The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history,…

cisco socialminer
0.01EPSS
CVE-2013-1188
Media 5.0

Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515.

cisco unified_communications_manager
0.01EPSS
CVE-2011-4022
Media 5.0

The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.

cisco intrusion_prevention_system
0.01EPSS
CVE-2021-1357
Media 6.5

Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities…

cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service
0.01EPSS
CVE-2021-1355
Media 6.5

Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities…

cisco unified_communications_manager · cisco unified_communications_manager_im_and_presence_service
0.01EPSS
CVE-2021-1242
Media 4.3

A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this …

cisco webex_teams
0.01EPSS
CVE-2017-6680
Alta 7.5

A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system. More Information: CSCvc76652. Known Affected Releases: 21.0.0.

cisco ultra_services_framework
0.01EPSS
CVE-2015-0684
Media 6.5

SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515.

cisco unified_communications_domain_manager
0.01EPSS
CVE-2014-8012
Media 4.3

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2020-3358
Alta 8.6

A vulnerability in the Secure Sockets Layer (SSL) VPN feature for Cisco Small Business RV VPN Routers could allow an unauthenticated, remote attacker to cause the device to unexpectedly restart, causing a denial of service (DoS) condition. The vulnerability is…

cisco rv340_dual_wan_gigabit_vpn_router_firmware · cisco rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware · cisco rv345_dual_wan_gigabit_vpn_router_firmware · cisco rv345p_dual_wan_gigabit_poe_vpn_router_firmware
0.01EPSS
CVE-2015-0656
Media 4.3

Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCum81269.

cisco network_analysis_module_firmware
0.01EPSS
CVE-2014-2191
Media 4.3

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun91113.

cisco broadband_access_center_telco_wireless_software
0.01EPSS
CVE-2013-5495
Media 4.3

Cross-site scripting (XSS) vulnerability in the web framework in the Application Server in Cisco Unified MeetingPlace allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui44681.

cisco unified_meetingplace
0.01EPSS
CVE-2018-0096
Media 5.9

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation in which one virtual domain user can view and modify another virtual domain conf…

cisco prime_infrastructure
0.01EPSS
CVE-2013-5515
Alta 7.8

The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7), 8.6.x before 8.6(1.12), 9.0.x before 9.0(2.6), and 9.1.x before 9.1(1.7) allows remote attackers to cause a …

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2021-1262
Alta 7.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.01EPSS
CVE-2016-1474
Media 4.3

Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" iss…

cisco prime_infrastructure
0.01EPSS
CVE-2019-1886
Alta 8.6

A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL…

cisco asyncos · cisco web_security_appliance
0.01EPSS
CVE-2016-1303
Alta 7.5

The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.

cisco 500_series_switch_firmware
0.01EPSS
CVE-2021-40116
Alta 8.6

Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset…

cisco secure_firewall_management_center · cisco secure_firewall_threat_defense · cisco snort
0.01EPSS
CVE-2021-34781
Alta 8.6

A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulne…

cisco firepower_management_center_virtual_appliance · cisco secure_firewall_threat_defense · cisco sourcefire_defense_center
0.01EPSS
CVE-2013-6704
Alta 7.1

Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686.

cisco ios_xe
0.01EPSS
CVE-2013-6703
Alta 7.1

The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2) SSLv3 packets, aka Bug ID CSCuh34787.

cisco ons_15454
0.01EPSS
CVE-2013-3461
Alta 7.1

Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service …

cisco unified_communications_manager
0.01EPSS
CVE-2014-3402
Media 5.0

The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (…

cisco intrusion_prevention_system
0.01EPSS