imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2011-0392
Alta 7.5

Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.

cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.02EPSS
CVE-2005-4794
Media 5.0

Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect off…

cisco application_and_content_networking_software · cisco ata · cisco ip_phone_7902 · cisco ip_phone_7905 · e altri 3
0.02EPSS
CVE-2018-0336
Alta 8.8

A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate privileges to the Administrator level. The vulnerability is due to insufficient authorization enforcement on b…

cisco prime_collaboration
0.02EPSS
CVE-2016-6370
Media 4.3

Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in an HTTP request, aka Bug ID CSCuz27255.

cisco hosted_collaboration_mediation_fulfillment
0.02EPSS
CVE-2006-1671
Media 5.0

Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug ID CSC…

cisco ons_15310-cl_series · cisco ons_15454_mspp · cisco ons_15600 · cisco optical_networking_systems_software · e altri 1
0.02EPSS
CVE-2002-0160
Media 5.0

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL …

cisco secure_access_control_server
0.02EPSS
CVE-2018-0260
Media 5.3

A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and download the contents of certain web application virtual directories. The vulnerability is due to lack of proper input validation and authorizat…

cisco mate_live
0.02EPSS
CVE-2011-0380
Alta 7.5

Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.

cisco telepresence_manager
0.02EPSS
CVE-2015-6412
Critica 9.8

Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.

cisco modular_encoding_platform_d9036_software
0.02EPSS
CVE-2014-8020
Media 5.0

Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU consumption, and performance degradation or service outage) via a flood of malformed TCP packets and UDP packets, aka Bug ID CSCup25276.

cisco unified_communications_domain_manager
0.02EPSS
CVE-2017-6630
Media 5.3

A vulnerability in the Session Initiation Protocol (SIP) implementation of Cisco IP Phone 8851 11.0(0.1) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to an abnormal SIP message. An attac…

cisco ip_phone_8800_series_firmware
0.02EPSS
CVE-2021-1299
Alta 8.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.02EPSS
CVE-2021-1298
Alta 8.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more informa…

cisco catalyst_sd-wan_manager · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller_firmware
0.02EPSS
CVE-2021-1150
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_firmware · e altri 1
0.02EPSS
CVE-2021-1149
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_firmware · e altri 1
0.02EPSS
CVE-2021-1148
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_firmware · e altri 1
0.02EPSS
CVE-2021-1147
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_firmware · e altri 1
0.02EPSS
CVE-2021-1146
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilit…

cisco application_extension_platform · cisco rv110w_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_firmware · e altri 1
0.02EPSS
CVE-2015-0619
Media 5.0

Memory leak in the embedded web server in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (memory consumption and SSL outage) via multiple crafted HTTP requests, aka Bug ID CSCue0545…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2015-0581
Alta 7.5

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonst…

cisco prime_service_catalog
0.02EPSS
CVE-2021-40114
Media 6.8

Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d…

cisco secure_firewall_management_center · cisco secure_firewall_threat_defense · cisco unified_threat_defense · snort snort
0.02EPSS
CVE-2018-0329
Media 5.3

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data from an affected device via SNMP. The vul…

cisco wide_area_application_services
0.02EPSS
CVE-2015-6425
Media 5.0

The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.

cisco unified_communications_manager
0.02EPSS
CVE-2015-4284
Media 5.0

The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.

cisco ios_xr
0.02EPSS
CVE-2014-3369
Alta 7.1

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.

cisco expressway_software · cisco telepresence_video_communication_server_software
0.02EPSS