imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2008-0532
Alta 10.0

Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located i…

cisco acs_for_windows · cisco acs_solution_engine · cisco user_changeable_password
0.57EPSS
CVE-2008-0027
Alta 10.0

Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attacke…

cisco unified_callmanager · cisco unified_communications_manager
0.57EPSS
CVE-2019-16012
Alta 8.1

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attack…

cisco sd-wan_firmware
0.54EPSS
CVE-2024-20440
Alta 7.5

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a…

cisco smart_license_utility
0.52EPSS
CVE-2019-15980
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit…

cisco data_center_network_manager
0.50EPSS
CVE-2018-15439
Critica 9.8

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected softwar…

cisco sf200-24_firmware · cisco sf200-24fp_firmware · cisco sf200-24p_firmware · cisco sf200-48_firmware · e altri 110
0.50EPSS
CVE-2018-0258
Critica 9.8

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects th…

cisco prime_data_center_network_manager · cisco prime_infrastructure
0.49EPSS
CVE-2022-20828
Media 6.5

A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER mod…

cisco asa_firepower
0.48EPSS
CVE-2019-15984
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would n…

cisco data_center_network_manager
0.47EPSS
CVE-2019-1636
Alta 7.8

A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating…

cisco webex_teams
0.47EPSS
CVE-2019-15276
Media 6.5

A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTT…

cisco wireless_lan_controller_software
0.46EPSS
CVE-2018-0114
Alta 7.5

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JW…

cisco node-jose
0.43EPSS
CVE-2020-3331
Critica 9.8

A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to im…

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.42EPSS
CVE-2011-0966
Media 6.8

Directory traversal vulnerability in cwhp/auditLog.do in the Homepage Auditing component in Cisco CiscoWorks Common Services 3.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, aka Bug ID CSCto35577.

cisco ciscoworks_common_services
0.41EPSS
CVE-2019-1898
Media 5.3

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP req…

cisco rv110w_firmware · cisco rv130w_firmware · cisco rv215w_firmware
0.41EPSS
CVE-2019-1936
Alta 7.2

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the…

cisco integrated_management_controller_supervisor · cisco ucs_director · cisco ucs_director_express_for_big_data
0.39EPSS
CVE-2020-3240
Alta 7.3

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.39EPSS
CVE-2019-15977
Alta 7.5

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. F…

cisco data_center_network_manager
0.38EPSS
CVE-2023-20209
Media 6.5

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection …

cisco telepresence_video_communication_server
0.38EPSS
CVE-2019-15978
Alta 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operatin…

cisco data_center_network_manager
0.37EPSS
CVE-2017-12285
Media 5.3

A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected software do…

cisco prime_network_analysis_module
0.37EPSS
CVE-2023-20126
Critica 9.8

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to a missing authentication process within th…

cisco spa112_firmware
0.37EPSS
CVE-2016-6435
Media 6.5

The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.

cisco secure_firewall_management_center
0.37EPSS
CVE-2012-0284
Alta 9.3

Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first ar…

cisco linksys_playerpt_activex_control
0.36EPSS
CVE-2021-1384
Media 6.5

A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. This vulnerability is due to incomplete validation of …

cisco ios_xe
0.35EPSS