EN

Vulnerabilità Cisco

6647 CVE

CVE-2005-2181
Alta 7.5

Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

cisco ip_phone_7940_firmware · cisco ip_phone_7960_firmware
0.01EPSS
CVE-2023-20164
Media 6.5

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must ha…

cisco identity_services_engine
0.01EPSS
CVE-2023-20163
Media 6.5

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must ha…

cisco identity_services_engine
0.01EPSS
CVE-2021-1614
Media 5.3

A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to gain access to information stored in MPLS buffer memory. This vulnerability is due to insufficient …

cisco sd-wan
0.01EPSS
CVE-2021-1422
Alta 7.7

A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker or an unauthenticated attacker in a man-in-the-middle positi…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.01EPSS
CVE-2021-34703
Media 6.8

A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability i…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2021-34699
Alta 7.7

A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. A…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2014-8006
Media 4.3

The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.

cisco isb8320-e_high-definition_ip-only_dvr
0.01EPSS
CVE-2013-3426
Media 5.0

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.

cisco unified_ip_phone_9951 · cisco unified_ip_phone_9971 · cisco unified_ip_phones_9900_series_firmware
0.01EPSS
CVE-2019-1627
Media 6.5

A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. T…

cisco integrated_management_controller · cisco unified_computing_system
0.01EPSS
CVE-2014-2184
Media 5.0

The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCun74352.

cisco unified_communications_manager
0.01EPSS
CVE-2013-5538
Media 5.0

The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary files via a direct request, aka Bug ID CSCui67506.

cisco identity_services_engine · cisco identity_services_engine_software
0.01EPSS
CVE-2013-3398
Media 5.0

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and fil…

cisco prime_central_for_hosted_collaboration_solution
0.01EPSS
CVE-2013-1232
Media 5.0

The HTTP implementation in Cisco WebEx Node for MCS, WebEx Meetings Server, and WebEx Node for ASR 1000 Series allows remote attackers to read the contents of uninitialized memory locations via a crafted request, aka Bug IDs CSCue36672, CSCue31363, CSCuf17466,…

cisco webex_meetings_server · cisco webex_node_for_asr_1000_series · cisco webex_node_for_mcs
0.01EPSS
CVE-2013-1231
Media 5.0

The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka Bug IDs CSCue36664 and CSCue36629.

cisco webex_meetings_server · cisco webex_node_for_mcs
0.01EPSS
CVE-2013-1214
Media 5.0

The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546.

cisco unified_contact_center_express_editor_software
0.01EPSS
CVE-2012-1348
Media 5.0

Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka …

cisco wide_area_application_services
0.01EPSS
CVE-2014-8015
Media 4.0

The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.

cisco identity_services_engine_software
0.01EPSS
CVE-2013-1108
Media 4.0

Cisco WebEx Training Center allows remote authenticated users to remove hands-on lab-session reservations via a crafted URL, aka Bug ID CSCzu81064.

cisco webex_training_center
0.01EPSS
CVE-2021-1489
Media 6.5

A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This vulnera…

cisco firepower_device_manager
0.01EPSS
CVE-2016-9209
Media 4.3

A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive Security Appliance (…

cisco firepower_services_for_adaptive_security_appliance
0.01EPSS
CVE-2023-20162
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.01EPSS
CVE-2023-20158
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.01EPSS
CVE-2023-20157
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.01EPSS
CVE-2023-20156
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.01EPSS