imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2015-4303
Media 6.5

Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2015-0586
Alta 7.8

The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router (aka Cisco Internet Router) devices allows remote attackers to cause a denial of service (NBAR process hang) v…

cisco ios
0.02EPSS
CVE-2006-3288
Media 5.0

Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and overwrite arbi…

cisco wireless_control_system
0.02EPSS
CVE-2016-1410
Alta 7.5

Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or (2) hosting a meeting, aka Bug ID CSCux84312.

cisco webex_meeting_center
0.02EPSS
CVE-2010-4681
Alta 7.5

Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to bypass SMTP inspection via vectors involving a prepended space character, aka Bug ID CSCte14901.

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.02EPSS
CVE-2010-4678
Alta 7.5

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permit packets to pass before the configuration has been loaded, which might allow remote attackers to bypass intended access restrictions by sending network traffic durin…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500
0.02EPSS
CVE-2017-12254
Media 6.1

A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of s…

cisco unified_intelligence_center
0.02EPSS
CVE-2014-3370
Alta 7.1

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.

cisco expressway_software · cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2015-4221
Media 4.0

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecifie…

cisco unified_communications_manager_im_and_presence_service
0.02EPSS
CVE-2018-0385
Alta 7.5

A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the Snort process unexpected…

cisco secure_firewall_management_center
0.02EPSS
CVE-2015-6415
Alta 7.1

Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757.

cisco unified_computing_system
0.02EPSS
CVE-2015-0681
Alta 7.1

The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3, 15.1(3)SVF4a, and 15.2(2)JB1 and IOS XE 2.5.x, 2.6.x, 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, and 3.5.xS before 3.6.0S; 3.1.xSG, 3.2.xSG, and 3.3.…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2015-6397
Alta 8.8

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv130w_wireless-n_multifunction_vpn_router_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.02EPSS
CVE-2001-1210
Media 6.4

Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community s…

cisco ubr920 · cisco ubr924 · cisco ubr925
0.02EPSS
CVE-2010-0582
Alta 7.8

Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (interface queue wedge) via malformed H.323 packets, aka Bug ID CSCta19962.

cisco ios
0.02EPSS
CVE-2018-0245
Media 5.3

A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to in…

cisco wireless_lan_controller_software
0.02EPSS
CVE-2017-6791
Alta 7.5

A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of…

cisco unified_communications_manager
0.02EPSS
CVE-2017-6763
Alta 7.5

A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected ap…

cisco meeting_server
0.02EPSS
CVE-2018-0305
Alta 8.6

A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability exists because the aff…

cisco firepower_9000_firmware · cisco nexus_5000_firmware · cisco nexus_7000_firmware · cisco nexus_9000_firmware · e altri 1
0.02EPSS
CVE-1999-1466
Alta 7.5

Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.

cisco ios
0.02EPSS
CVE-2015-0618
Alta 7.1

Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension head…

cisco carrier_routing_system · cisco ios_xr
0.02EPSS
CVE-2012-4617
Alta 7.1

The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug…

cisco ios · cisco ios_xe · cisco ios_xr
0.02EPSS
CVE-2015-6255
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-Mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via a crafted chat message, aka Bug ID CSCuo89051.

cisco unified_web_and_e-mail_interaction_manager
0.02EPSS
CVE-2020-3127
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation …

cisco webex_meetings · cisco webex_meetings_online · cisco webex_meetings_server · cisco webex_network_recording_player
0.02EPSS
CVE-2001-1071
Media 5.0

Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.

cisco catos · cisco ios
0.02EPSS