imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2013-1104
Alta 9.0

The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP User-Agent header, aka Bug ID CSCuc15636.

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2500_wireless_lan_controller · cisco 4100_wireless_lan_controller · e altri 5
0.04EPSS
CVE-2021-1264
Critica 9.6

A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exploit …

cisco catalyst_center
0.04EPSS
CVE-2006-0368
Alta 7.8

Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause…

cisco call_manager
0.04EPSS
CVE-2016-1351
Alta 7.5

The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.

cisco ios · cisco nx-os
0.04EPSS
CVE-2008-1152
Alta 7.8

The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.

cisco cisco_ios · cisco ios
0.04EPSS
CVE-2013-2684
Media 6.1

Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

cisco linksys_e4200_firmware
0.04EPSS
CVE-2019-1756
Alta 7.2

A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes use…

cisco ios · cisco ios_xe
0.04EPSS
CVE-2021-1297
Alta 7.5

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2021-1296
Alta 7.5

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that …

cisco rv160_vpn_router_firmware · cisco rv160w_wireless-ac_vpn_router_firmware · cisco rv260_vpn_router_firmware · cisco rv260p_vpn_router_with_poe_firmware · e altri 1
0.04EPSS
CVE-2016-6374
Critica 9.8

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.

cisco cloud_services_platform_2100
0.04EPSS
CVE-2005-0195
Media 5.0

Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.

cisco ios
0.04EPSS
CVE-2016-1457
Alta 8.8

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA) Software on 5500-X devices with FirePOWER Services 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 allows…

cisco secure_firewall_management_center
0.04EPSS
CVE-2016-1430
Alta 8.8

Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.

cisco rv180_vpn_router_firmware · cisco rv180w_vpn_router_firmware
0.04EPSS
CVE-2006-5660
Alta 7.5

Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.

cisco security_agent_management_center
0.04EPSS
CVE-2012-6007
Media 4.3

Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to inject arbitrary web script or HTML via the headline parameter, aka Bug ID…

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2500_wireless_lan_controller · cisco 4100_wireless_lan_controller · e altri 5
0.04EPSS
CVE-2013-6976
Media 6.8

Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication of administrators for requests that change a password via the Password and PasswordReEnter parameters, aka Bug I…

cisco epc3925
0.04EPSS
CVE-2018-15441
Critica 9.4

A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An a…

cisco prime_license_manager
0.04EPSS
CVE-2019-15999
Media 6.3

A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerabili…

cisco data_center_network_manager
0.04EPSS
CVE-2010-0597
Alta 9.0

Unspecified vulnerability in Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 allows remote authent…

cisco mediator_framework
0.04EPSS
CVE-2010-4671
Alta 7.8

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source…

cisco ios
0.04EPSS
CVE-2018-0228
Alta 8.6

A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an af…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.04EPSS
CVE-2006-3594
Alta 7.5

Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542.

cisco unified_callmanager
0.04EPSS
CVE-2014-2198
Alta 10.0

Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root accounts by extracting this key from a binary f…

cisco unified_cdm_platform_software · cisco unified_communications_domain_manager
0.04EPSS
CVE-2013-6979
Media 5.4

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, …

cisco ios_xe
0.04EPSS
CVE-2025-20303
Media 5.4

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient vali…

cisco identity_services_engine
0.04EPSS