imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2019-1899
Media 5.3

A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HT…

cisco rv110w_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.03EPSS
CVE-2010-1577
Alta 7.8

Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL.

cisco content_delivery_system · cisco internet_streamer
0.03EPSS
CVE-2011-2024
Alta 10.0

Cisco Network Registrar before 7.2 has a default administrative password, which makes it easier for remote attackers to obtain access via a TCP session, aka Bug ID CSCsm50627.

cisco cns_network_registrar
0.03EPSS
CVE-2010-3038
Alta 10.0

Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier for remote attackers to obtain access via the (a) FTP or (b) S…

cisco unified_videoconferencing_system_5110 · cisco unified_videoconferencing_system_5110_firmware · cisco unified_videoconferencing_system_5115 · cisco unified_videoconferencing_system_5115_firmware
0.03EPSS
CVE-2011-2555
Alta 10.0

Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default password for the root administrator account, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtr76182.

cisco telepresence_recording_server_software
0.03EPSS
CVE-2020-3341
Alta 7.5

A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buf…

canonical ubuntu_linux · cisco clam_antivirus · debian debian_linux · fedoraproject fedora
0.03EPSS
CVE-2013-1180
Alta 9.0

Buffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allows remote authenticated users to execute arbitrary code via a crafted SNMP reques…

cisco mds_9000 · cisco nexus_7000 · cisco nexus_7000_10-slot · cisco nexus_7000_18-slot · e altri 2
0.03EPSS
CVE-2013-1179
Alta 9.0

Multiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices 4.x and 5.x before 5.2(5) allow remote authenticated users to execute ar…

cisco mds_9000 · cisco nexus_7000 · cisco nexus_7000_10-slot · cisco nexus_7000_18-slot · e altri 2
0.03EPSS
CVE-2009-1561
Media 6.8

Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password vi…

cisco wrt54gc
0.03EPSS
CVE-2019-16028
Critica 9.8

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vu…

cisco secure_firewall_management_center
0.03EPSS
CVE-2011-0372
Alta 10.0

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640.

cisco telepresence_system_1000 · cisco telepresence_system_1100 · cisco telepresence_system_1300_series · cisco telepresence_system_3000 · e altri 3
0.03EPSS
CVE-2018-0442
Alta 7.5

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to retrieve memory contents, which could lead to the disclosur…

cisco wireless_lan_controller_software
0.03EPSS
CVE-2018-0325
Alta 7.5

A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series phones and Cisco IP Phone 8800 Series phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an a…

cisco ip_phone_7800_firmware · cisco ip_phone_8800_firmware
0.03EPSS
CVE-2018-0280
Alta 7.5

A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation o…

cisco meeting_server
0.03EPSS
CVE-2007-1063
Alta 10.0

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.

cisco unified_ip_phone_firmware_7906g · cisco unified_ip_phone_firmware_7911g · cisco unified_ip_phone_firmware_7941g · cisco unified_ip_phone_firmware_7961g · e altri 2
0.03EPSS
CVE-2005-2244
Media 5.0

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory al…

cisco call_manager
0.03EPSS
CVE-2016-1350
Alta 7.5

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

cisco ios_xe · lenovo thinkcentre_e75s_firmware · samsung x14j_firmware · sun opensolaris · e altri 2
0.03EPSS
CVE-2009-0637
Alta 7.1

The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files…

cisco ios · cisco ios_xr
0.03EPSS
CVE-2015-4216
Media 5.0

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different custom…

cisco content_security_management_virtual_appliance · cisco email_security_virtual_appliance · cisco web_security_virtual_appliance
0.03EPSS
CVE-2020-3219
Alta 8.8

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. The vulnerability is due to i…

cisco ios_xe
0.03EPSS
CVE-2014-3360
Alta 7.8

Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allow remote attackers to cause a denial of service (device reload) v…

cisco ios · cisco ios_xe
0.03EPSS
CVE-2019-15985
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would n…

cisco data_center_network_manager
0.03EPSS
CVE-2019-15979
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operatin…

cisco data_center_network_manager
0.03EPSS
CVE-2016-9198
Alta 7.5

A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199)…

cisco identity_services_engine
0.03EPSS
CVE-2008-3805
Alta 8.5

Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (de…

cisco ios
0.03EPSS