imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2011-0387
Alta 8.0

The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to…

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software
0.02EPSS
CVE-2018-0199
Media 6.1

A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script in attribu…

cisco jabber
0.02EPSS
CVE-2012-2496
Media 6.8

A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on 64-bit Linux platforms does not properly restrict use of Java components, which allows remote attackers to exec…

cisco anyconnect_secure_mobility_client
0.02EPSS
CVE-2009-0615
Alta 9.0

Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related t…

cisco application_control_engine_device_manager · cisco application_networking_manager
0.02EPSS
CVE-2021-1401
Alta 8.8

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an…

cisco wap125_firmware · cisco wap131_firmware · cisco wap150_firmware · cisco wap351_firmware · e altri 2
0.02EPSS
CVE-2011-3285
Media 5.0

CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecifi…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2021-1602
Alta 8.2

A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected d…

cisco small_business_rv_series_router_firmware
0.02EPSS
CVE-2017-12316
Alta 7.5

A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient …

cisco identity_services_engine_software
0.02EPSS
CVE-2014-0728
Alta 7.5

SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum05313.

cisco unified_communications_manager
0.02EPSS
CVE-2017-6790
Media 6.8

A vulnerability in the Session Initiation Protocol (SIP) on the Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the targeted appliance. The vulnerability is due…

cisco telepresence_video_communication_server
0.02EPSS
CVE-2014-3303
Media 4.0

The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser histo…

cisco webex_meetings_server
0.02EPSS
CVE-2014-3280
Media 4.0

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified A…

cisco unified_communications_domain_manager
0.02EPSS
CVE-2014-3282
Media 4.0

The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive number-translation information …

cisco unified_communications_domain_manager
0.02EPSS
CVE-2013-5560
Media 5.4

The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted packets, …

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2013-5559
Media 6.8

Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.

cisco anyconnect_secure_mobility_client
0.02EPSS
CVE-2006-3289
Bassa 2.6

Cross-site scripting (XSS) vulnerability in the login page of the HTTP interface for the Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a…

cisco wireless_control_system
0.02EPSS
CVE-2006-0764
Media 5.1

The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server ho…

cisco anomaly_guard_module · cisco guard · cisco traffic_anomaly_detector_module
0.02EPSS
CVE-2019-1697
Media 6.8

A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affect…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2019-1721
Media 6.5

A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condi…

cisco telepresence_video_communication_server
0.02EPSS
CVE-2015-4225
Media 4.0

Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID…

cisco nx-os
0.02EPSS
CVE-2015-0760
Media 4.0

The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2015-4214
Media 4.0

Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.

cisco unified_meetingplace
0.02EPSS
CVE-2013-5554
Alta 7.5

Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773.

cisco wide_area_application_services_mobile
0.02EPSS
CVE-2017-6651
Alta 7.5

A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on cust…

cisco webex_meetings_server
0.02EPSS
CVE-1999-1000
Media 5.0

The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.

cisco cache_engine
0.02EPSS