EN

Vulnerabilità Cisco

6647 CVE

CVE-2014-3284
Media 6.1

Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180.

cisco asr_1001 · cisco asr_1002 · cisco asr_1002-x · cisco asr_1002_fixed_router · e altri 5
0.01EPSS
CVE-2019-1975
Media 6.1

A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An a…

cisco hyperflex_hx220c_af_m5_firmware · cisco hyperflex_hx220c_edge_m5_firmware · cisco hyperflex_hx220c_m5_firmware · cisco hyperflex_hx240c_af_m5_firmware · e altri 1
0.01EPSS
CVE-2019-1830
Media 4.9

A vulnerability in Locally Significant Certificate (LSC) management for the Cisco Wireless LAN Controller (WLC) could allow an authenticated, remote attacker to cause the device to unexpectedly restart, which causes a denial of service (DoS) condition. The att…

cisco wireless_lan_controller_software
0.01EPSS
CVE-2014-3322
Media 6.1

Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.

cisco asr_9000_rsp440_router · cisco asr_9001 · cisco asr_9006 · cisco asr_9010 · e altri 4
0.01EPSS
CVE-2011-3318
Alta 7.8

Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP …

cisco video_surveillance_2421 · cisco video_surveillance_2500 · cisco video_surveillance_2600 · cisco video_surveillance_software
0.01EPSS
CVE-2011-3287
Alta 7.8

Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory an…

cisco jabber_extensible_communications_platform
0.01EPSS
CVE-2011-2562
Alta 7.8

Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (service outage) v…

cisco unified_communications_manager
0.01EPSS
CVE-2011-0949
Alta 7.8

Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.

cisco ios_xr
0.01EPSS
CVE-2011-0943
Alta 7.8

Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4 packet, aka Bug ID CSCth44147.

cisco ios_xr
0.01EPSS
CVE-2010-2825
Alta 7.8

Unspecified vulnerability in the SIP inspection feature on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2(2.x) before A2(2.3), and A2(3.x) before A2(3.1) for Catalyst 6500 series switches and 7600 series routers, and…

cisco ace_4710 · cisco ace_module
0.01EPSS
CVE-2010-2983
Alta 7.8

The workgroup bridge (aka WGB) functionality in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (dropped connection) via a series of spoofed EAPoL-Logoff frames, related to an "EAPoL logoff…

cisco unified_wireless_network_solution_software
0.01EPSS
CVE-2010-2980
Alta 7.8

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 5508 series controllers allows remote attackers to cause a denial of service (pbuf exhaustion and device crash) via fragmented traffic, aka Bug ID CSCtd26794.

cisco unified_wireless_network_solution_software
0.01EPSS
CVE-2010-2979
Alta 7.8

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 5508 series controllers allows remote attackers to cause a denial of service (buffer leak and device crash) via ARP requests that trigger an ARP storm, aka Bug ID CSCte43508.

cisco unified_wireless_network_solution_software
0.01EPSS
CVE-2009-4921
Alta 7.8

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (traceback) via malformed TCP packets, aka Bug ID CSCsm84110.

cisco asa_5580
0.01EPSS
CVE-2009-4915
Alta 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via unknown network traffic, as demonstrated by a "connection stress test…

cisco asa_5580
0.01EPSS
CVE-2009-4911
Alta 7.8

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device crash) via vectors involving SSL VPN and PPPoE transactions, aka Bug ID CSCsm7795…

cisco asa_5580
0.01EPSS
CVE-2015-6276
Media 5.0

Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct request to …

cisco telepresence_system_software_ix
0.01EPSS
CVE-2014-3310
Media 4.3

The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCu…

cisco webex_meeting_center · cisco webex_meetings_server
0.01EPSS
CVE-2017-6793
Media 6.5

A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to view sensitive information on the system. The vulnerability is due to insufficient protection of restricted info…

cisco prime_collaboration_provisioning
0.01EPSS
CVE-2017-6778
Media 6.5

A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as…

cisco ultra_services_platform
0.01EPSS
CVE-2017-6697
Media 6.5

A vulnerability in the web interface of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive system credentials that are stored in an affected system. More Information: CSCvd76339. Known Affected Releases: 2.2(9.…

cisco elastic_services_controller
0.01EPSS
CVE-2017-6691
Media 6.5

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information on an affected system. More Information: CSCvd29403. Known Affected Releases: 2.3(2).

cisco elastic_services_controller
0.01EPSS
CVE-2013-6710
Media 6.8

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.

cisco webex_training_center
0.01EPSS
CVE-2011-4007
Media 5.4

Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka B…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2011-2586
Media 5.4

The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.

cisco ios
0.01EPSS