imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2015-0621
Alta 7.8

Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reload) via an unspecified series of TCP packets, aka Bug ID CSCur50347.

cisco telepresence_mcu_4500_series_software
0.02EPSS
CVE-2015-0592
Alta 7.8

The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672.

cisco ios
0.02EPSS
CVE-2013-1103
Alta 7.8

Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (Access Point reload) via crafted SIP packets, aka Bug ID CSCts87659.

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2500_wireless_lan_controller · cisco 4100_wireless_lan_controller · e altri 5
0.02EPSS
CVE-2013-1102
Alta 7.8

The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3 before 7.3.101.0 allows remote attackers to cause a denial of service (device rel…

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2500_wireless_lan_controller · cisco 4100_wireless_lan_controller · e altri 5
0.02EPSS
CVE-2018-0328
Media 6.1

A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. Th…

cisco unified_communications_manager
0.02EPSS
CVE-2015-0747
Media 4.3

Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.

cisco headend_digital_broadband_delivery_system · cisco headend_system_release · cisco videoscape_conductor
0.02EPSS
CVE-2011-2058
Alta 7.5

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger m…

cisco ios
0.02EPSS
CVE-2015-6352
Media 4.3

Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a series of requests, aka Bug ID CSCut6789…

cisco hosted_collaboration_solution · cisco unified_communications_domain_manager
0.02EPSS
CVE-2013-5526
Alta 7.1

Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.

cisco unified_ip_phone_9951 · cisco unified_ip_phone_9971
0.02EPSS
CVE-2021-1538
Media 4.7

A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attac…

cisco common_services_platform_collector
0.02EPSS
CVE-2006-3596
Media 5.0

The device driver for Intel-based gigabit network adapters in Cisco Intrusion Prevention System (IPS) 5.1(1) through 5.1(p1), as installed on various Cisco Intrusion Prevention System 42xx appliances, allows remote attackers to cause a denial of service (kerne…

cisco ips_sensor_software
0.02EPSS
CVE-2006-1928
Media 5.0

Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, a…

cisco ios_xr
0.02EPSS
CVE-2006-1631
Media 5.0

Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests.

cisco content_services_switch_11500
0.02EPSS
CVE-2018-0379
Alta 7.8

Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via em…

cisco webex_business_suite · cisco webex_meeting_server · cisco webex_meetings_online
0.02EPSS
CVE-2015-4296
Media 5.0

Nexus Data Broker (NDB) on Cisco Nexus 3000 devices with software 6.0(2)A6(1) allows remote attackers to cause a denial of service (Java process restart) via crafted connections to the Java application, aka Bug ID CSCut87006.

cisco nx-os
0.02EPSS
CVE-2010-4687
Media 5.0

STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which allows remote attackers to cause a denial of service (port hang) by simultaneously ending two calls that were con…

cisco ios
0.02EPSS
CVE-2007-0965
Alta 7.8

Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.

cisco firewall_services_module
0.02EPSS
CVE-2020-3397
Alta 8.6

A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) conditio…

cisco nx-os
0.02EPSS
CVE-2020-3224
Alta 8.8

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to inject IOS commands to an affected device. The injected commands should require a higher privilege leve…

cisco ios_xe
0.02EPSS
CVE-2018-0355
Media 6.1

A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affected system. The vulnerability is due to…

cisco unified_communications_manager
0.02EPSS
CVE-2015-4293
Media 5.0

The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (CPU consumption or packet loss) via fragmented (1) IPv4 or (2) IPv6 packets that trigger ATTN-3-SYNC_TIMEOUT errors after reassembly fa…

cisco ios_xe
0.02EPSS
CVE-2020-3562
Alta 8.6

A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnera…

cisco secure_firewall_threat_defense
0.02EPSS
CVE-2020-3130
Media 6.5

A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vu…

cisco unity_connection
0.02EPSS
CVE-2014-2140
Media 5.0

Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (card reset) via a TCP FIN attack that triggers file-descriptor exhaustion and a failure to open a CAL pipe, aka Bug ID CSCug97348.

cisco cisco_ons_15454_system_software · cisco ons_15454
0.02EPSS
CVE-2002-1107
Alta 7.5

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.

cisco vpn_client
0.02EPSS