imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2015-4305
Media 4.0

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended system-database read restrictions, and discover credentials or SNMP communities for arbitrary tenant domains, via a crafted URL,…

cisco prime_collaboration_assurance
0.02EPSS
CVE-2020-3128
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation …

cisco webex_meetings · cisco webex_meetings_online · cisco webex_meetings_server · cisco webex_network_recording_player
0.02EPSS
CVE-2019-1763
Alta 7.5

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service …

cisco ip_conference_phone_8832_firmware · cisco ip_phone_8800_firmware · cisco ip_phone_8821-ex_firmware · cisco ip_phone_8821_firmware
0.02EPSS
CVE-2016-6391
Alta 7.5

Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.

cisco ios
0.02EPSS
CVE-2016-6378
Alta 7.5

Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.

cisco ios_xe
0.02EPSS
CVE-2016-1483
Alta 7.5

Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.

cisco webex_meetings_server
0.02EPSS
CVE-2016-6399
Alta 7.5

Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb16317.

cisco ace_4700_series_application_control_engine_appliance · cisco ace_4700_series_application_control_engine_appliance_a1 · cisco ace_4700_series_application_control_engine_appliance_a3 · cisco ace_4700_series_application_control_engine_appliance_a4 · e altri 5
0.02EPSS
CVE-2016-1478
Alta 7.5

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

cisco ios
0.02EPSS
CVE-2015-6396
Alta 7.8

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv130w_wireless-n_multifunction_vpn_router_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.02EPSS
CVE-2016-1426
Alta 7.5

Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.

cisco ios_xr
0.02EPSS
CVE-2015-0725
Alta 7.8

Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Internet Streaming (aka VDS-IS or CDS-IS) before 3.3.1 R7 and 4.x before 4.0.0 R4 allow remote attackers to cause a…

cisco videoscape_distribution_suite_for_internet_streaming · cisco videoscape_distribution_suite_service_broker
0.02EPSS
CVE-2015-0754
Alta 7.5

Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810.

cisco finesse
0.02EPSS
CVE-2014-0682
Media 4.9

Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meetings, or (2) terminate a meeting without having a host role, via a crafted URL, aka Bug ID CSCuj42346.

cisco webex_meetings_server
0.02EPSS
CVE-2021-40120
Media 6.5

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute t…

cisco application_extension_platform · cisco ios_xr
0.02EPSS
CVE-2020-3179
Alta 7.5

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vul…

cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · cisco asa_5515-x_firmware · e altri 9
0.02EPSS
CVE-2017-3827
Media 5.8

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters …

cisco email_security_appliance_firmware · cisco web_security_appliance
0.02EPSS
CVE-2018-15466
Media 5.3

A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the inter…

cisco policy_suite_for_mobile
0.02EPSS
CVE-2021-1479
Alta 7.8

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v…

cisco catalyst_sd-wan_manager · cisco sd-wan_vmanage
0.02EPSS
CVE-2016-1382
Alta 7.5

Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu…

cisco web_security_appliance_\(wsa\)
0.02EPSS
CVE-2016-1369
Alta 7.5

The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0 misconfigures kernel logging, which allows remote attackers to cause a denial of service (resource consump…

cisco asa_with_firepower_services
0.02EPSS
CVE-2015-6421
Alta 7.5

cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device r…

cisco wide_area_application_services
0.02EPSS
CVE-2015-6320
Alta 7.5

The IP ingress packet handler on Cisco Aironet 1800 devices with software 8.1(112.3) and 8.1(112.4) allows remote attackers to cause a denial of service via a crafted header in an IP packet, aka Bug ID CSCuv63138.

cisco aironet_access_point_software
0.02EPSS
CVE-2020-3421
Alta 8.6

Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handli…

cisco ios_xe
0.02EPSS
CVE-2009-0059
Alta 7.8

The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of s…

cisco 4400_wireless_lan_controller · cisco catalyst_3750_series_integrated_wireless_lan_controller · cisco catalyst_6500_series_integrated_wireless_lan_controller · cisco catalyst_7600_series_wireless_lan_controller · e altri 1
0.02EPSS
CVE-2001-1038
Media 5.0

Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.

cisco sn_5420_storage_router_firmware
0.02EPSS