imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2015-6282
Alta 7.8

Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug ID CSCu…

cisco ios_xe
0.02EPSS
CVE-2015-0769
Alta 7.8

Cisco IOS XR 4.0.1 through 4.2.0 for CRS-3 Carrier Routing System allows remote attackers to cause a denial of service (NPU ASIC scan and line-card reload) via crafted IPv6 extension headers, aka Bug ID CSCtx03546.

cisco ios_xr_software
0.02EPSS
CVE-2015-6399
Media 6.8

The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.

cisco integrated_management_controller_supervisor
0.02EPSS
CVE-2017-3809
Media 5.8

A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.…

cisco secure_firewall_management_center
0.02EPSS
CVE-2014-3276
Media 4.0

Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service …

cisco identity_services_engine_software
0.02EPSS
CVE-2019-1740
Alta 8.6

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on …

cisco ios · cisco ios_xe
0.02EPSS
CVE-2018-15446
Media 5.3

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID a…

cisco meeting_server
0.02EPSS
CVE-2017-12214
Alta 8.8

A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is…

cisco unified_customer_voice_portal
0.02EPSS
CVE-2020-3131
Media 6.5

A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the client to crash, resulting in a denial of service (DoS) condition. The attacker needs a valid developer account to exploit this vulnerability…

cisco webex_teams
0.02EPSS
CVE-2007-5568
Alta 7.1

Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (…

cisco adaptive_security_appliance_software · cisco firewall_services_module
0.02EPSS
CVE-2016-1302
Alta 8.8

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RB…

cisco nx-os · samsung x14j_firmware · sun opensolaris · zyxel gs1900-10hp_firmware · e altri 1
0.02EPSS
CVE-2017-15805
Alta 7.5

Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

cisco small_business_sa520_firmware · cisco small_business_sa540_firmware
0.02EPSS
CVE-2011-2584
Alta 7.5

Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Configurations, (3) Video Encoding Formats, and (4) Transcoding administration pages, and cause a denial of servi…

cisco show_and_share
0.02EPSS
CVE-2020-3451
Media 4.7

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2015-6327
Alta 7.8

The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) allow…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2018-0181
Alta 7.3

A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis se…

cisco cisco_policy_suite_diameter_routing_agent · cisco cisco_policy_suite_for_mobile
0.02EPSS
CVE-2016-6397
Critica 9.8

A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause…

cisco ip_interoperability_and_collaboration_system
0.02EPSS
CVE-2020-3531
Critica 9.8

A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authentica…

cisco iot_field_network_director
0.02EPSS
CVE-2013-1148
Alta 7.8

The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) v…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2014-3329
Media 4.3

Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum86620.

cisco prime_data_center_network_manager
0.02EPSS
CVE-2006-0367
Media 6.5

Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "cr…

cisco call_manager
0.02EPSS
CVE-2019-1903
Media 6.5

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit…

cisco security_manager
0.02EPSS
CVE-2019-1743
Alta 8.8

A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could explo…

cisco ios_xe
0.02EPSS
CVE-2002-1595
Media 5.0

Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization.

cisco sn_5420_storage_router_firmware
0.02EPSS
CVE-2014-2170
Alta 9.0

Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to tshell (aka tcsh) scripts, aka Bug ID CSCue60202.

cisco telepresence_tc_software · cisco telepresence_te_software
0.02EPSS