imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2018-0448
Critica 9.8

A vulnerability in the identity management service of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and take complete control of identity management functions. The vulnerability is due …

cisco digital_network_architecture_center
0.02EPSS
CVE-2017-6653
Alta 7.5

A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to re…

cisco identity_services_engine
0.02EPSS
CVE-2017-6633
Alta 7.5

A vulnerability in the TCP throttling process of Cisco UCS C-Series Rack Servers 3.0(0.234) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate-limiti…

cisco unified_computing_system
0.02EPSS
CVE-2017-3837
Alta 8.1

An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confiden…

cisco meeting_server
0.02EPSS
CVE-2019-1760
Media 6.8

A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload. The vulnerability is due to the processing of malformed smart probe packets. An attacker c…

cisco ios_xe
0.02EPSS
CVE-2017-12328
Media 5.8

A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the SIP process unexpectedly restarts. All active phon…

cisco ip_phone_8800_series_firmware
0.02EPSS
CVE-2017-12217
Media 5.3

A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution (SAE) Gateways could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condi…

cisco asr_5500_firmware
0.02EPSS
CVE-2014-3330
Media 5.0

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, …

cisco nexus_9000 · cisco nx-os
0.02EPSS
CVE-2014-0657
Media 4.0

The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal …

cisco unified_communications_manager
0.02EPSS
CVE-2013-5487
Alta 7.8

DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCue77029.

cisco prime_data_center_network_manager
0.02EPSS
CVE-2021-1300
Critica 9.8

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

cisco catalyst_sd-wan_manager · cisco ios_xe_sd-wan · cisco sd-wan_firmware · cisco sd-wan_vbond_orchestrator · e altri 1
0.02EPSS
CVE-2011-2585
Media 6.5

Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote authenticated users to upload and execute arbitrary code by leveraging video upload privileges, aka Bug ID CSCto69857.

cisco show_and_share
0.02EPSS
CVE-2003-0259
Media 5.0

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client · cisco vpn_3015_concentrator · cisco vpn_3030_concentator · e altri 2
0.02EPSS
CVE-2003-0260
Media 5.0

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.

cisco vpn_3000_concentrator_series_software · cisco vpn_3002_hardware_client · cisco vpn_3015_concentrator · cisco vpn_3030_concentator · e altri 2
0.02EPSS
CVE-2010-2976
Alta 10.0

The controller in Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 has (1) a default SNMP read-only community of public, (2) a default SNMP read-write community of private, and a value of "default" for the (3) SNMP v3 username, (4) SNMP v3 au…

cisco unified_wireless_network_solution_software
0.02EPSS
CVE-2013-1122
Media 5.0

Cisco NX-OS on the Nexus 7000, when a certain Overlay Transport Virtualization (OTV) configuration is used, allows remote attackers to cause a denial of service (M1-Series module reload) via crafted packets, aka Bug ID CSCud15673.

cisco nexus_7000 · cisco nx-os
0.02EPSS
CVE-2020-3196
Alta 8.6

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust memory res…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · e altri 10
0.02EPSS
CVE-2013-6688
Media 6.3

Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka B…

cisco unified_communications_manager
0.02EPSS
CVE-2021-1579
Alta 8.1

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to …

cisco application_policy_infrastructure_controller · cisco cloud_application_policy_infrastructure_controller
0.02EPSS
CVE-2019-1814
Alta 8.6

A vulnerability in the interactions between the DHCP and TFTP features for Cisco Small Business 300 Series (Sx300) Managed Switches could allow an unauthenticated, remote attacker to cause the device to become low on system memory, which in turn could lead to …

cisco sf300-08_firmware · cisco sf300-24_firmware · cisco sf300-24mp_firmware · cisco sf300-24p_firmware · e altri 23
0.02EPSS
CVE-2019-1679
Media 5.0

A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to …

cisco telepresence_conductor · cisco telepresence_video_communication_server
0.02EPSS
CVE-2018-15420
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15417
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15416
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2018-15415
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_32 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS