imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2015-4182
Media 5.5

The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.

cisco identity_services_engine_software
0.02EPSS
CVE-2014-2169
Alta 9.0

Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.

cisco telepresence_tc_software · cisco telepresence_te_software
0.02EPSS
CVE-2015-0768
Media 6.5

The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute comma…

cisco prime_network_control_system
0.02EPSS
CVE-2019-1806
Alta 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attack…

cisco esw2-350g52dc_firmware · cisco esw2-550x48dc_firmware · cisco sf200-24_firmware · cisco sf200-24p_firmware · e altri 101
0.02EPSS
CVE-2013-3455
Media 5.0

Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCug16732.

cisco finesse
0.02EPSS
CVE-2016-1362
Alta 7.5

Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCun86747.

cisco aireos
0.02EPSS
CVE-2016-1296
Alta 7.5

The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.

cisco web_security_appliance
0.02EPSS
CVE-2013-6963
Media 4.3

Cross-site scripting (XSS) vulnerability in the registration component in Cisco WebEx Training Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207.

cisco webex_training_center
0.02EPSS
CVE-2013-6690
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCu…

cisco prime_collaboration
0.02EPSS
CVE-2022-20753
Media 4.7

A vulnerability in web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-suppli…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-1999-1216
Alta 7.5

Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.

cisco router
0.02EPSS
CVE-2014-0677
Media 5.0

The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bug ID CSCul88851.

cisco nx-os
0.02EPSS
CVE-2017-3884
Media 6.5

A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to access sensitive data. The attacker does not need administrator credentials and could use t…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.02EPSS
CVE-2017-3824
Media 6.8

A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Cisco cBR-8 Converged Broadband Rou…

cisco ios_xe
0.02EPSS
CVE-2010-2025
Media 6.8

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests tha…

cisco scientific_atlanta_webstar_dpc2100r2
0.02EPSS
CVE-2019-1868
Alta 7.5

A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files within the web-based manag…

cisco webex_meetings_server
0.02EPSS
CVE-2020-3336
Alta 7.2

A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access …

cisco roomos · cisco telepresence_collaboration_endpoint
0.02EPSS
CVE-2011-4659
Alta 10.0

Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtw698…

cisco ip_video_phone_e20 · cisco telepresence_e20_software
0.02EPSS
CVE-2014-2126
Alta 8.5

Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 before 9.1(3.4) allows remote authenticated users to gain privileges by leveraging level-0 ASDM access, aka Bug ID C…

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2000-0486
Media 5.0

Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.

cisco ios · cisco tacacs\+
0.02EPSS
CVE-2019-1693
Media 6.5

A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vu…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2021-1275
Critica 9.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthor…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2015-4219
Media 4.0

Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information v…

cisco identity_services_engine_software · cisco secure_access_control_system
0.02EPSS
CVE-2018-15369
Media 6.8

A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2018-0398
Critica 9.8

Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack. Cisco Bug IDs: CSCvg71018.

cisco finesse
0.02EPSS