imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2006-1961
Alta 7.5

Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Managem…

cisco ciscoworks_2000_service_management_solution · cisco ethernet_subscriber_solution_engine · cisco hosting_solution_engine · cisco user_registration_tool · e altri 1
0.03EPSS
CVE-2015-4207
Media 5.0

Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intended attendance restrictions by visiting a meeting-registration page, aka Bug ID CSCus62147.

cisco webex_meeting_center
0.03EPSS
CVE-2019-12652
Alta 7.5

A vulnerability in the ingress packet processing function of Cisco IOS Software for Cisco Catalyst 4000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due…

cisco ios
0.03EPSS
CVE-2008-1156
Media 5.1

Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data…

cisco cisco_ios · cisco ios
0.03EPSS
CVE-2021-1618
Media 6.5

Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to i…

cisco intersight_virtual_appliance
0.03EPSS
CVE-2016-6452
Critica 9.8

A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. Cisco Prime Home versions 5.1.1.6 and ear…

cisco prime_home
0.03EPSS
CVE-2018-0112
Critica 9.0

A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation…

cisco webex_business_suite_31 · cisco webex_business_suite_32 · cisco webex_meetings · cisco webex_meetings_server
0.03EPSS
CVE-2005-0597
Media 5.0

Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection."

cisco application_and_content_networking_software
0.03EPSS
CVE-2016-9208
Media 6.5

A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected devic…

cisco emergency_responder
0.03EPSS
CVE-2015-6319
Critica 9.8

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.

cisco rv_series_router_firmware · sun opensolaris
0.03EPSS
CVE-2018-0170
Alta 7.5

A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exi…

cisco ios_xe
0.03EPSS
CVE-2018-0157
Alta 8.6

A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exp…

cisco ios_xe
0.03EPSS
CVE-2001-1105
Alta 7.5

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

cisco icdn · dell bsafe_ssl-j
0.03EPSS
CVE-2006-3286
Alta 7.5

The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaintext within unspecified files, which allows remote authenticated users to access the database (aka bug CSCsd1595…

cisco wireless_control_system
0.03EPSS
CVE-2006-3287
Alta 7.5

Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and earlier uses a default administrator username "root" and password "public," which allows remote attackers to gain access (aka bug CSCse21391).

cisco wireless_control_system
0.03EPSS
CVE-2006-3285
Alta 7.5

The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bu…

cisco wireless_control_system
0.03EPSS
CVE-2008-2739
Alta 7.8

The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerabi…

cisco ios
0.03EPSS
CVE-2021-1385
Media 6.5

A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This v…

cisco ios · cisco ios_xe
0.03EPSS
CVE-2018-0136
Alta 8.6

A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a…

cisco ios_xr
0.03EPSS
CVE-2017-3864
Alta 8.6

A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during …

cisco ios · cisco ios_xe
0.03EPSS
CVE-2020-3554
Alta 7.5

A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devic…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.03EPSS
CVE-2017-6647
Media 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Temporary File information on an affected system. The vulnerability exists because the affected software doe…

cisco remote_expert_manager
0.03EPSS
CVE-2017-6646
Media 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system. The vulnerability exists because the affected software does not suf…

cisco remote_expert_manager
0.03EPSS
CVE-2017-6645
Media 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Temporary Directory information on an affected system. The vulnerability exists because the affected…

cisco remote_expert_manager
0.03EPSS
CVE-2017-6644
Media 5.3

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not sufficien…

cisco remote_expert_manager
0.03EPSS