imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2020-3195
Alta 7.5

A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected de…

cisco adaptive_security_appliance_software · cisco asa_5505_firmware · cisco asa_5510_firmware · cisco asa_5512-x_firmware · e altri 10
0.02EPSS
CVE-2012-0369
Alta 7.8

Cisco Wireless LAN Controller (WLC) devices with software 6.0 and 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (device reload) via a sequence of IPv6 packets, aka Bug ID CSCtt07949.

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2106_wireless_lan_controller · cisco 2112_wireless_lan_controller · e altri 9
0.02EPSS
CVE-2022-20827
Critica 9.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information ab…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · e altri 5
0.02EPSS
CVE-2018-0087
Media 5.6

A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerability i…

cisco asyncos
0.02EPSS
CVE-2015-6422
Media 4.0

The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID CSCuu10981.

cisco unified_communications_domain_manager
0.02EPSS
CVE-2015-4315
Media 5.5

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML docum…

cisco telepresence_video_communication_server_software
0.02EPSS
CVE-2020-3371
Media 6.3

A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficie…

cisco integrated_management_controller
0.02EPSS
CVE-2021-1518
Media 6.3

A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient …

cisco firepower_device_manager_on-box
0.02EPSS
CVE-2018-0164
Alta 8.6

A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker could exp…

cisco ios_xe
0.02EPSS
CVE-2017-9483
Critica 9.8

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users to obtain root access to the Application Processor (AP) Linux system via shell metacharacters in commands.

cisco dpc3939_firmware
0.02EPSS
CVE-2015-6377
Alta 7.8

Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379.

cisco virtual_topology_system
0.02EPSS
CVE-2022-20871
Media 6.3

A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform a command injection and elevate privilege…

cisco asyncos
0.02EPSS
CVE-2021-1414
Media 6.3

Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.02EPSS
CVE-2019-1983
Media 5.3

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some in…

cisco asyncos · cisco content_security_management_appliance · cisco email_security_appliance
0.02EPSS
CVE-2015-4206
Media 4.3

Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.

cisco unified_communications_manager
0.02EPSS
CVE-2018-15409
Alta 7.8

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software im…

cisco webex_business_suite_31 · cisco webex_business_suite_33 · cisco webex_meetings_online · cisco webex_meetings_server
0.02EPSS
CVE-2015-4188
Media 5.0

SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug IDs CSCuu29910, CSCuu29928, and CSCuu59104.

cisco prime_collaboration
0.02EPSS
CVE-2013-6701
Media 5.0

The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via…

cisco cisco_ons_15454_system_software · cisco ons_15454 · cisco ons_15454_mspp · cisco ons_15454_mstp · e altri 4
0.02EPSS
CVE-2013-5470
Media 5.0

Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID CSCuh12488.

cisco secure_access_control_system
0.02EPSS
CVE-2014-2200
Alta 7.1

Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH session to a management interface, aka Bug ID CSCti11629.

cisco nx-os
0.02EPSS
CVE-2020-3529
Alta 8.6

A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a de…

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.02EPSS
CVE-2015-0697
Media 5.8

Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…

cisco telepresence_tc_software
0.02EPSS
CVE-2017-3814
Media 5.8

A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5.4.0 …

cisco secure_firewall_management_center
0.02EPSS
CVE-2014-3346
Media 6.3

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) does not validate an unspecified parameter, which allows remote authenticated users to cause a denial of service (service crash) via a craf…

cisco transport_gateway_installation_software
0.02EPSS
CVE-2014-3287
Media 4.0

SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to execute arbitrary SQL commands via crafted filename parameters in a URL, aka Bug ID C…

cisco unified_communications_manager
0.02EPSS