EN

Vulnerabilità Cisco

6642 CVE

CVE-2012-5032
Media 6.4

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discardin…

cisco ios
0.01EPSS
CVE-2008-2165
Media 4.3

Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

cisco building_broadband_service_manager
0.01EPSS
CVE-2010-3048
Alta 7.5

Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition.

cisco unified_personal_communicator
0.01EPSS
CVE-2003-0305
Media 5.0

The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.

cisco ios
0.01EPSS
CVE-2001-0754
Media 5.0

Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets.

cisco cbos
0.01EPSS
CVE-2001-0055
Media 5.0

CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.

cisco broadband_operating_system · cisco cisco_6xx_routers
0.01EPSS
CVE-2001-0057
Media 5.0

Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.

cisco broadband_operating_system · cisco cisco_6xx_routers
0.01EPSS
CVE-2021-34720
Alta 8.6

A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause device packet memory to become exhausted or cause t…

cisco ios_xr
0.01EPSS
CVE-2021-1565
Alta 8.6

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of se…

cisco catalyst_9800_firmware · cisco embedded_wireless_controller · cisco ios_xe
0.01EPSS
CVE-2019-1881
Media 4.7

A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vuln…

cisco industrial_network_director
0.01EPSS
CVE-2012-0362
Media 4.3

The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bu…

cisco ios
0.01EPSS
CVE-2021-1400
Alta 8.8

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an…

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · e altri 2
0.01EPSS
CVE-2016-1445
Media 5.3

Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2013-1134
Alta 7.1

The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning atta…

cisco unified_communications_manager
0.01EPSS
CVE-2021-1353
Media 5.8

A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An…

cisco staros · cisco virtualized_packet_core-single_instance
0.01EPSS
CVE-2021-1272
Alta 8.8

A vulnerability in the session validation feature of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. This vulnerabi…

cisco data_center_network_manager
0.01EPSS
CVE-2018-0436
Alta 8.7

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficien…

cisco webex_teams
0.01EPSS
CVE-2013-3417
Media 5.0

The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.

cisco video_surveillance_operations_manager
0.01EPSS
CVE-2013-1123
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the server in Cisco Unified MeetingPlace 7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuc65411 and CSCue18706.

cisco unified_meetingplace
0.01EPSS
CVE-2017-9491
Media 5.3

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC394…

cisco dpc3939_firmware · cisco dpc3939b_firmware · cisco dpc3941t_firmware · commscope arris_tg1682g_firmware
0.01EPSS
CVE-2020-3370
Media 5.8

A vulnerability in URL filtering of Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to bypass URL filtering on an affected device. The vulnerability is due to insufficient input validation. An attacker could ex…

cisco email_security_appliance
0.01EPSS
CVE-2016-6419
Alta 7.5

SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.

cisco secure_firewall_management_center
0.01EPSS
CVE-2010-2977
Alta 10.0

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not properly implement TLS and SSL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtd01611.

cisco unified_wireless_network_solution_software
0.01EPSS
CVE-2021-34785
Media 6.5

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

cisco broadworks_commpilot_application_software
0.01EPSS
CVE-2021-1350
Media 5.3

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit t…

cisco umbrella
0.01EPSS