imPC@ndo EN

Vulnerabilità Cisco

6641 CVE

CVE-2013-1213
Media 5.0

Cisco NX-OS on the Nexus 1000V does not assign the proper priority to heartbeat messages from a Virtual Ethernet Module (VEM) to a Virtual Supervisor Module (VSM), which allows remote attackers to cause a denial of service (false VEM unavailability report) via…

cisco nexus_1000v · cisco nx-os
0.02EPSS
CVE-2013-1193
Media 5.0

The Secure Shell (SSH) implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properly terminate sessions, which allows remote attackers to cause a denial of service (SSH service outage) by re…

cisco adaptive_security_appliance_software · cisco firewall_services_module
0.02EPSS
CVE-2015-0770
Media 5.0

CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut793…

cisco telepresence_tc_software
0.02EPSS
CVE-2018-0198
Media 5.3

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerab…

cisco unified_communications_manager
0.02EPSS
CVE-2015-0670
Media 6.4

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSC…

cisco spa300_firmware · cisco spa500_firmware · cisco spa_301_1_line_ip_phone · cisco spa_302d · e altri 11
0.02EPSS
CVE-2020-3302
Alta 8.1

A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to overwrite files on the file system of an affected device. The vulnerability is due to insufficient input validation. An attacker …

cisco secure_firewall_management_center
0.02EPSS
CVE-2015-4321
Media 5.0

The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(1) mishandles cases where an IP address belongs to an internal interface but is also in the ASA routing table, …

cisco adaptive_security_appliance_software
0.02EPSS
CVE-2013-5472
Alta 7.1

The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2004-0308
Alta 10.0

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows a superuser whose account is locked out, disabled, or suspended to gain unauthorized access via a Telnet connec…

cisco optical_networking_systems_software
0.02EPSS
CVE-2018-0223
Media 6.1

A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerabil…

cisco security_manager
0.02EPSS
CVE-2018-0219
Media 6.1

A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an aff…

cisco unified_computing_system_director
0.02EPSS
CVE-2018-0212
Media 6.1

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev…

cisco identity_services_engine
0.02EPSS
CVE-2018-0144
Media 6.1

A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected …

cisco prime_data_center_network_manager
0.02EPSS
CVE-2016-6455
Alta 7.5

A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote attacker to cause a subset of the subscriber sessions to be disconnected, resulting in a partial denial of ser…

cisco asr_5000_software
0.02EPSS
CVE-2016-6358
Alta 7.5

A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affec…

cisco email_security_appliance
0.02EPSS
CVE-2019-15288
Alta 8.8

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vul…

cisco roomos · cisco telepresence_codec · cisco telepresence_collaboration_endpoint
0.02EPSS
CVE-2015-0711
Media 5.0

The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.

cisco staros
0.02EPSS
CVE-2015-0672
Media 5.0

The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.

cisco ios_xr
0.02EPSS
CVE-2014-2143
Media 5.0

The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.

cisco ios · cisco ios_xe
0.02EPSS
CVE-2021-34795
Critica 10.0

Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a de…

cisco catalyst_pon_switch_cgp-ont-1p_firmware · cisco catalyst_pon_switch_cgp-ont-4p_firmware · cisco catalyst_pon_switch_cgp-ont-4pv_firmware · cisco catalyst_pon_switch_cgp-ont-4pvc_firmware · e altri 1
0.02EPSS
CVE-2012-2486
Alta 8.3

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 al…

cisco telepresence_manager · cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software · cisco telepresence_recording_server · e altri 11
0.02EPSS
CVE-2020-3419
Media 6.5

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens b…

cisco webex_meetings_server
0.02EPSS
CVE-2020-3170
Media 5.3

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is se…

cisco nx-os
0.02EPSS
CVE-2015-6429
Media 5.0

The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.

cisco ios · cisco ios_xe
0.02EPSS
CVE-2015-6386
Media 5.0

The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer…

cisco web_security_appliance
0.02EPSS