imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2014-0653
Media 4.3

The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to trigger authentication-state modifications via a crafted NetBIOS logout probe response, aka Bug ID CSCuj45340.

cisco adaptive_security_appliance
0.07EPSS
CVE-2025-20283
Media 6.5

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input.…

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.07EPSS
CVE-2016-1327
Critica 9.8

Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935.

cisco dpc2203_cable_modem_firmware · cisco epc2203_cable_modem_firmware
0.07EPSS
CVE-2017-3792
Critica 9.8

A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability …

cisco telepresence_mcu_software
0.07EPSS
CVE-2018-15427
Critica 9.8

A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root…

cisco video_surveillance_manager
0.07EPSS
CVE-2011-0926
Alta 9.3

A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a diff…

cisco secure_desktop
0.07EPSS
CVE-2007-1257
Alta 10.0

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed from the NAM's own IP address.

cisco catalyst_6000_ws-svc-nam-1 · cisco catalyst_6000_ws-svc-nam-2 · cisco catalyst_6000_ws-x6380-nam · cisco catalyst_6500_ws-svc-nam-1 · e altri 6
0.07EPSS
CVE-2003-1109
Alta 7.5

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arb…

cisco ios · cisco ip_phone_7940 · cisco ip_phone_7960 · cisco pix_firewall_software
0.07EPSS
CVE-2016-1291
Critica 9.8

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

cisco evolved_programmable_network_manager · cisco prime_infrastructure · sun opensolaris
0.07EPSS
CVE-2018-0423
Alta 8.1

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of ser…

cisco rv110w_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.07EPSS
CVE-2006-3906
Media 5.0

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expira…

cisco adaptive_security_appliance_software · cisco ios · cisco pix_asa_ids · cisco pix_firewall · e altri 17
0.07EPSS
CVE-2016-6432
Alta 8.1

A vulnerability in the Identity Firewall feature of Cisco ASA Software before 9.6(2.1) could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to a buffer overflow in the af…

cisco adaptive_security_appliance_software
0.07EPSS
CVE-2024-20454
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying oper…

cisco spa_301_firmware · cisco spa_303_firmware · cisco spa_501g_firmware · cisco spa_502g_firmware · e altri 7
0.07EPSS
CVE-2017-12246
Alta 8.6

A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service …

cisco adaptive_security_appliance_software
0.07EPSS
CVE-2007-2832
Media 4.3

Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern …

cisco call_manager
0.06EPSS
CVE-2020-26139
Media 5.3

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-servi…

arista c-100_firmware · arista c-110_firmware · arista c-120_firmware · arista c-130_firmware · e altri 162
0.06EPSS
CVE-2011-0383
Alta 10.0

The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for u…

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software · cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.06EPSS
CVE-2007-2462
Alta 10.0

Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 before 7.2(2)8, when using Layer 2 Tunneling Protocol (L2TP) or Remote Management Access, allows remote attackers to bypass LDAP authentication and gain privileges via unknown vec…

cisco adaptive_security_appliance_software · cisco pix
0.06EPSS
CVE-2017-12337
Critica 9.8

A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability …

cisco emergency_responder · cisco finesse · cisco hosted_collaboration_solution · cisco mediasense · e altri 7
0.06EPSS
CVE-2007-5580
Alta 10.0

Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on p…

cisco security_agent
0.06EPSS
CVE-2001-0566
Media 5.0

Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

cisco catalyst_2900
0.06EPSS
CVE-2026-20180
Critica 9.9

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On…

cisco identity_services_engine
0.06EPSS
CVE-2018-0426
Critica 9.8

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensit…

cisco rv110w_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.06EPSS
CVE-2017-6741
Alta 8.8

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected devi…

cisco ios_xe
0.06EPSS
CVE-2013-2682
Media 4.3

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.

cisco linksys_e4200_firmware
0.06EPSS