imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2009-4913
Media 5.0

The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far side of the box," which might allow remote attackers to bypass intended access restrictions via IPv6 packets, ak…

cisco asa_5580
0.02EPSS
CVE-2020-3521
Media 5.3

A vulnerability in a specific REST API of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-…

cisco data_center_network_manager
0.02EPSS
CVE-2011-0946
Alta 7.8

The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic,…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2010-1580
Alta 7.8

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 …

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2010-1579
Alta 7.8

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 …

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2010-1578
Alta 7.8

Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 …

cisco adaptive_security_appliance · cisco adaptive_security_appliance_software
0.02EPSS
CVE-2017-3835
Alta 8.8

A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).

cisco identity_services_engine_software
0.02EPSS
CVE-2016-1446
Alta 8.8

SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.

cisco webex_meetings_server
0.02EPSS
CVE-2015-6416
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479.

cisco unified_web_and_e-mail_interaction_manager
0.02EPSS
CVE-2015-0732
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco AsyncOS on the Web Security Appliance (WSA) 9.0.0-193; Email Security Appliance (ESA) 8.5.6-113, 9.1.0-032, 9.1.1-000, and 9.6.0-000; and Content Security Management Appliance (SMA) 9.1.0-033 allows remote atta…

cisco content_security_management_virtual_appliance · cisco email_security_appliance_firmware · cisco web_security_appliance
0.02EPSS
CVE-2011-0944
Alta 7.8

Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (device reload) via malformed IPv6 packets, aka Bug ID CSCtj41194.

cisco ios
0.02EPSS
CVE-2010-2835
Alta 7.8

Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.…

cisco ios · cisco ios_xe · cisco unified_communications_manager
0.02EPSS
CVE-2022-20790
Media 6.5

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary file…

cisco unified_communications_manager
0.02EPSS
CVE-2012-5992
Media 6.8

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screen…

cisco 2000_wireless_lan_controller · cisco 2100_wireless_lan_controller · cisco 2500_wireless_lan_controller · cisco 4100_wireless_lan_controller · e altri 5
0.02EPSS
CVE-2018-0458
Media 6.1

A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected devi…

cisco prime_collaboration_assurance
0.02EPSS
CVE-2018-0411
Media 6.1

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an af…

cisco unified_communications_manager
0.02EPSS
CVE-2018-0406
Media 6.1

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected or Document Object Model based (DOM-based) cross-site scripting (XSS) attack against a user of th…

cisco web_security_appliance
0.02EPSS
CVE-2018-0366
Media 6.1

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affe…

cisco web_security_appliance
0.02EPSS
CVE-2018-0356
Media 6.1

A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input valid…

cisco webex_meetings
0.02EPSS
CVE-2018-0354
Media 6.1

A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient …

cisco unity_connection
0.02EPSS
CVE-2018-0339
Media 6.1

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to …

cisco identity_services_engine_software
0.02EPSS
CVE-2018-0327
Media 6.1

A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to i…

cisco identity_services_engine_software
0.02EPSS
CVE-2018-0289
Media 6.1

A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application manag…

cisco identity_services_engine_software
0.02EPSS
CVE-2014-3297
Media 4.0

Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer…

cisco cloud_portal
0.02EPSS
CVE-2014-2154
Media 5.0

Memory leak in the SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (memory consumption and instability) via crafted SIP packets, aka Bug ID CSCuf67469.

cisco adaptive_security_appliance_software
0.02EPSS