imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2010-4682
Alta 7.8

Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (memory consumption) by making multiple incorrect LDAP authentication attempts, aka Bug ID CSCtf29867.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2019-1687
Alta 7.5

A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a de…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.03EPSS
CVE-2018-0348
Alta 7.2

A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this…

cisco vbond_orchestrator · cisco vedge-1000_firmware · cisco vedge-100_firmware · cisco vedge-2000_firmware · e altri 8
0.03EPSS
CVE-2008-2057
Media 5.4

The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x before 8.1(1)2 allows remote attackers to cause a denial of service via a crafted pac…

cisco adaptive_security_appliance_software · cisco pix_security_appliance
0.03EPSS
CVE-2016-1468
Alta 8.8

The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.

cisco telepresence_video_communication_server
0.03EPSS
CVE-2015-0713
Alta 9.0

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94…

cisco telepresence_advanced_media_gateway · cisco telepresence_ip_gateway · cisco telepresence_ip_vcr_1.0_converter · cisco telepresence_ip_vcr_2.4 · e altri 6
0.03EPSS
CVE-2008-0531
Alta 9.3

Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.

cisco session_initiation_protocol_\(sip\)_firmware · cisco skinny_client_control_protocol_\(sccp\)_firmware
0.03EPSS
CVE-2019-1703
Alta 8.6

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for the Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulti…

cisco secure_firewall_threat_defense
0.03EPSS
CVE-2007-5552
Alta 9.3

Integer overflow in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is…

cisco ios
0.03EPSS
CVE-2020-3284
Critica 9.8

A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is …

cisco a99-rp2-se_firmware · cisco a99-rp2-tr_firmware · cisco a99-rp3-se_firmware · cisco a99-rp3-tr_firmware · e altri 40
0.03EPSS
CVE-2016-1472
Alta 7.5

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of service (interface outage) via a crafted HTTP request, aka Bug ID CSCuz76238.

cisco small_business_220_series_smart_plus_switches
0.03EPSS
CVE-2018-0405
Alta 7.5

A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to conduct a directory path traversal attack o…

cisco rv180w_firmware · cisco rv220w_firmware
0.03EPSS
CVE-2020-3437
Media 6.5

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limitin…

cisco sd-wan_firmware
0.03EPSS
CVE-2007-2463
Alta 7.8

Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)17 allows remote attackers to cause a denial of service (device reload) via unknown vectors related to VPN connection termination and password…

cisco adaptive_security_appliance_software · cisco pix
0.03EPSS
CVE-2014-2197
Alta 9.0

The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote authenticated users to modify administrative crede…

cisco unified_cdm_application_software · cisco unified_communications_domain_manager
0.03EPSS
CVE-2018-15430
Alta 7.2

A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. …

cisco telepresence_video_communication_server
0.03EPSS
CVE-2018-0330
Alta 8.8

A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges. The vulnerability is due to a fai…

cisco nx-os
0.03EPSS
CVE-2021-1337
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpect…

cisco rv016_multi-wan_vpn_router_firmware · cisco rv042_dual_wan_vpn_router_firmware · cisco rv042g_dual_gigabit_wan_vpn_router_firmware · cisco rv082_dual_wan_vpn_router_firmware · e altri 2
0.03EPSS
CVE-2016-6379
Alta 7.5

Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2016-6386
Alta 7.5

Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005.

cisco ios_xe · cisco ios_xe_16.1 · cisco ios_xe_3.2ja · cisco ios_xe_3.3sg · e altri 2
0.03EPSS
CVE-2016-6355
Alta 7.5

Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.

cisco ios_xr
0.03EPSS
CVE-2016-1466
Alta 7.5

Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packe…

cisco unified_communications_manager_im_and_presence_service
0.03EPSS
CVE-2016-1312
Alta 7.5

The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of HTTPS …

cisco asa_5500_csc-ssm_firmware
0.03EPSS
CVE-2020-3144
Critica 9.8

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authenti…

cisco rv110w_firmware · cisco rv130_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.03EPSS
CVE-2014-8019
Media 5.0

Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted URL, aka Bug ID CSCuo90148.

cisco enterprise_content_delivery_system
0.03EPSS