imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2021-1290
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2021-1289
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2020-3357
Critica 9.8

A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…

cisco rv340_dual_wan_gigabit_vpn_router_firmware · cisco rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware · cisco rv345_dual_wan_gigabit_vpn_router_firmware · cisco rv345p_dual_wan_gigabit_poe_vpn_router_firmware
0.04EPSS
CVE-2013-3444
Alta 9.0

The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x …

cisco application_and_content_networking_system_software · cisco enterprise_content_delivery_network_software · cisco internet_streamer_content_delivery_system · cisco videoscape_delivery_system_for_internet_streamer · e altri 4
0.04EPSS
CVE-2017-6714
Critica 9.8

A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attack…

cisco ultra_services_framework_staging_server
0.04EPSS
CVE-2006-4911
Alta 7.5

Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets".

cisco ips_sensor_software
0.04EPSS
CVE-2011-0382
Alta 10.0

The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.

cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.04EPSS
CVE-2009-3457
Media 5.0

Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a …

cisco ace_web_application_firewall · cisco ace_xml_gateway
0.04EPSS
CVE-2016-6384
Alta 7.5

Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257.

cisco ios · cisco ios_xe
0.04EPSS
CVE-2010-3270
Media 6.8

Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since…

cisco webex_meeting_center
0.04EPSS
CVE-2002-0908
Media 5.0

Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request.

cisco ids_device_manager
0.04EPSS
CVE-2021-1292
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2007-1062
Alta 10.0

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the adminis…

cisco unified_ip_conference_station_7935_firmware · cisco unified_ip_conference_station_firmware_7936
0.04EPSS
CVE-2017-11588
Critica 9.8

On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to …

cisco residential_gateway_firmware
0.04EPSS
CVE-2018-0310
Critica 9.8

A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to obtain sensitive information from memory or cause a denial of service (DoS) condition on the affected prod…

cisco firepower_extensible_operating_system · cisco nx-os
0.04EPSS
CVE-2019-15992
Alta 7.2

A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root priv…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_management_center · cisco secure_firewall_threat_defense
0.04EPSS
CVE-2018-0410
Alta 8.6

A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an affected system. The vulnera…

cisco web_security_appliance
0.04EPSS
CVE-2020-3263
Alta 7.5

A vulnerability in Cisco Webex Meetings Desktop App could allow an unauthenticated, remote attacker to execute programs on an affected end-user system. The vulnerability is due to improper validation of input that is supplied to application URLs. The attacker …

cisco webex_meetings
0.04EPSS
CVE-2016-1421
Alta 7.5

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability exist…

cisco ip_phone_8800_series_firmware
0.04EPSS
CVE-2018-0313
Alta 8.8

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerability is due to incorr…

cisco nx-os
0.04EPSS
CVE-2018-0485
Alta 8.6

A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/E3 mo…

cisco ios · cisco ios_xe
0.04EPSS
CVE-2017-3791
Critica 10.0

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processing error in the role-based access control…

cisco cisco_prime_home
0.04EPSS
CVE-2018-0262
Alta 8.1

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect defau…

cisco meeting_server
0.04EPSS
CVE-2005-0196
Media 5.0

Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.

cisco ios
0.04EPSS
CVE-2004-1432
Media 5.0

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or…

cisco optical_networking_systems_software
0.04EPSS