imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2017-6746
Alta 7.2

A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid administrator credentials. Affec…

cisco web_security_appliance
0.04EPSS
CVE-2019-1759
Media 5.3

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. …

cisco ios_xe
0.04EPSS
CVE-2001-0669
Alta 7.5

Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU …

cisco catalyst_6000_intrusion_detection_system_module · cisco secure_intrusion_detection_system · enterasys dragon · iss realsecure_network_sensor · e altri 2
0.04EPSS
CVE-2015-6280
Alta 9.3

The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before 3.11.4S, 3.12S before 3.12.3S, 3.13S before 3.13.3S, and 3.14S before 3.14.1S does not properly implement RSA …

cisco ios · cisco ios_xe
0.04EPSS
CVE-2010-0145
Alta 10.0

Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka…

cisco ironport_encryption_appliance · cisco ironport_postx
0.04EPSS
CVE-2021-1140
Critica 9.8

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details…

cisco smart_software_manager_satellite
0.04EPSS
CVE-2021-1138
Critica 9.8

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details…

cisco smart_software_manager_satellite
0.04EPSS
CVE-2018-15454
Alta 8.6

A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to relo…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.04EPSS
CVE-2019-1861
Alta 7.2

A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attac…

cisco industrial_network_director
0.04EPSS
CVE-2003-0982
Alta 7.5

Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.

cisco application_and_content_networking_software · cisco content_distribution_manager_4630 · cisco content_distribution_manager_4650 · cisco content_distribution_manager_4670 · e altri 5
0.04EPSS
CVE-2007-2461
Alta 7.8

The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the…

cisco adaptive_security_appliance_software · cisco pix
0.04EPSS
CVE-2021-1142
Critica 9.8

Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details…

cisco smart_software_manager_satellite
0.04EPSS
CVE-2015-0653
Alta 10.0

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypa…

cisco expressway_software · cisco telepresence_conductor · cisco telepresence_video_communication_server_software
0.04EPSS
CVE-2019-1624
Alta 8.8

A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An a…

cisco sd-wan
0.04EPSS
CVE-2007-0479
Alta 7.8

Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.

cisco ios_transmission_control_protocol
0.04EPSS
CVE-2001-1097
Media 5.0

Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

cisco ios
0.04EPSS
CVE-2008-0536
Alta 7.8

Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) v…

cisco service_control_engine · icon-labs iconfidant_ssh
0.04EPSS
CVE-2007-4634
Alta 9.3

Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang …

cisco call_manager · cisco unified_communications_manager
0.04EPSS
CVE-2000-0984
Media 5.0

The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.

cisco ios
0.04EPSS
CVE-2006-3595
Alta 7.5

The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190.

cisco router_web_setup
0.04EPSS
CVE-2002-2208
Alta 7.8

Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results …

cisco ios · extended_interior_gateway_routing_protocol extended_interior_gateway_routing_protocol
0.04EPSS
CVE-2006-4097
Alta 7.8

Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request p…

cisco secure_access_control_server
0.04EPSS
CVE-2017-6616
Alta 8.8

A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not sufficie…

cisco integrated_management_controller_supervisor
0.04EPSS
CVE-2021-1295
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2021-1291
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS