imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2020-3454
Alta 7.2

A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges on the underlying operating system (OS). The vulnerability is due to insuffi…

cisco nx-os
0.03EPSS
CVE-2020-3212
Alta 7.2

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device. The vulnerability is due to improper input sanitiz…

cisco ios_xe
0.03EPSS
CVE-2014-3348
Media 5.0

The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.

cisco integrated_management_controller · cisco unified_computing_system_e140d · cisco unified_computing_system_e140dp · cisco unified_computing_system_e140s_m1 · e altri 4
0.03EPSS
CVE-2013-3445
Media 5.0

The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of service (CPU consumption or process crash) via a flood of malformed IP packets, aka Bug ID CSCug94572.

cisco identity_services_engine
0.03EPSS
CVE-2016-1454
Media 6.5

Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDA…

cisco nx-os
0.03EPSS
CVE-2020-3158
Critica 9.1

A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account …

cisco smart_software_manager_on-prem
0.03EPSS
CVE-2014-2177
Alta 9.0

The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted …

cisco rv120w · cisco rv120w_firmware · cisco rv180 · cisco rv180_firmware · e altri 3
0.03EPSS
CVE-2013-6972
Media 5.0

Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading HTML source code, aka Bug ID CSCul57126.

cisco webex_training_center
0.03EPSS
CVE-2007-4263
Alta 8.5

Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-based IOS allows remote authenticated users to read, write or overwrite any file on the device's filesystem via unknown vectors.

cisco ios
0.03EPSS
CVE-2010-4689
Alta 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, which allows remote attackers to bypass intended access restrictions via an unspecified type of network traffic th…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.03EPSS
CVE-2011-0389
Alta 7.8

Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software
0.03EPSS
CVE-2011-3304
Alta 7.8

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.2 before 7.2(5.3), 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.11), 8.3 before 8.3(2.23), 8.4 befo…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500 · cisco catalyst_6500 · e altri 1
0.03EPSS
CVE-2011-0391
Alta 7.8

Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205.

cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.03EPSS
CVE-2011-0390
Alta 7.8

The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534.

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software
0.03EPSS
CVE-2012-4659
Alta 7.1

The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.2 before 8.2(5.30) and 8.3 before 8.3(2.34) al…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco catalyst_6500 · cisco catalyst_6503-e · e altri 7
0.03EPSS
CVE-2011-2538
Alta 7.2

Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.

cisco telepresence_video_communication_server
0.03EPSS
CVE-2008-1155
Alta 10.0

Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs.…

cisco network_admission_control
0.03EPSS
CVE-2007-5382
Alta 10.0

The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileg…

cisco wireless_control_system · cisco wireless_lan_solution_engine
0.03EPSS
CVE-2007-2036
Alta 10.0

The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384…

cisco wireless_lan_controller_software
0.03EPSS
CVE-2011-3272
Alta 7.8

The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3.3.x, allows remote attackers to cause a denial of service (memory corruption and device reload) via malformed IP SLA packets, aka Bug ID CSCtk67073.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2018-0213
Alta 8.8

A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit t…

cisco identity_services_engine
0.03EPSS
CVE-2007-0960
Alta 9.0

Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.

cisco asa_5500 · cisco pix_firewall_software
0.03EPSS
CVE-2017-6681
Alta 7.5

A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system. More Information: CSC…

cisco ultra_services_framework
0.03EPSS
CVE-2011-3279
Alta 7.8

The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.

cisco ios · cisco ios_xe
0.03EPSS
CVE-2010-0568
Alta 7.1

Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.7), 8.1 before 8.1(2.40), and 8.2 before 8.2(2.1); and Cisco PIX 500 Series Security Appliance; allows remote attackers …

cisco asa_5500 · cisco pix_500
0.03EPSS