Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2015-4207

Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intended attendance restrictions by visiting a meeting-registration page, aka Bug ID CSCus62147.

6.4AI Score

0.001EPSS

2015-06-23 02:59 PM
29
cve
cve

CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398.

7AI Score

0.002EPSS

2015-06-24 10:59 AM
31
cve
cve

CVE-2015-4209

Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive information by obtaining a list of all meetings and then sending a calendar request for each one, aka Bug ID CSCur23913.

6.4AI Score

0.003EPSS

2015-06-23 02:59 PM
30
cve
cve

CVE-2015-4210

Cross-site scripting (XSS) vulnerability in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur03806.

5.8AI Score

0.001EPSS

2015-06-23 02:59 PM
28
cve
cve

CVE-2015-4211

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.

6.3AI Score

0.0004EPSS

2015-06-24 10:59 AM
39
cve
cve

CVE-2015-4212

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credentials, aka Bug ID CSCut17466.

6.4AI Score

0.001EPSS

2015-06-24 10:59 AM
26
cve
cve

CVE-2015-4213

Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.

6.4AI Score

0.001EPSS

2015-06-24 10:59 AM
41
cve
cve

CVE-2015-4214

Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.

6.3AI Score

0.001EPSS

2015-06-24 10:59 AM
29
cve
cve

CVE-2015-4215

Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of service (device crash) by triggering an exception during attempted forwarding of unspecified IPv6 packets to a non-IPv6 device, aka Bug ID CSCuj01046.

7AI Score

0.003EPSS

2015-06-24 10:59 AM
40
2
cve
cve

CVE-2015-4216

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easi...

7.1AI Score

0.001EPSS

2015-06-26 10:59 AM
35
cve
cve

CVE-2015-4217

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for rem...

6.7AI Score

0.002EPSS

2015-06-26 10:59 AM
41
cve
cve

CVE-2015-4218

The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.

6.2AI Score

0.001EPSS

2015-06-24 10:59 AM
32
cve
cve

CVE-2015-4219

Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid c...

6AI Score

0.001EPSS

2015-06-24 10:59 AM
37
cve
cve

CVE-2015-4220

Cross-site scripting (XSS) vulnerability in Cisco Unified Presence Server 9.1(1) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq03773.

5.9AI Score

0.001EPSS

2015-06-25 04:59 PM
30
cve
cve

CVE-2015-4221

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryp...

7.6AI Score

0.001EPSS

2015-06-26 10:59 AM
34
cve
cve

CVE-2015-4222

SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.

8.2AI Score

0.001EPSS

2015-06-26 10:59 AM
29
cve
cve

CVE-2015-4223

Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.

6.8AI Score

0.002EPSS

2015-06-25 04:59 PM
24
cve
cve

CVE-2015-4224

Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.

7.4AI Score

0.0004EPSS

2015-06-26 10:59 AM
30
cve
cve

CVE-2015-4225

Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.

6AI Score

0.001EPSS

2015-06-27 10:59 AM
36
cve
cve

CVE-2015-4226

The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976.

6.9AI Score

0.003EPSS

2015-06-30 03:59 PM
29
cve
cve

CVE-2015-4227

Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91838.

6.9AI Score

0.003EPSS

2015-06-30 10:59 AM
34
cve
cve

CVE-2015-4228

Cisco Digital Content Manager (DCM) 15.0.0 might allow remote ad servers to cause a denial of service (reboot) via malformed ad messages, aka Bug ID CSCur13999.

6.8AI Score

0.001EPSS

2015-07-02 02:59 PM
46
cve
cve

CVE-2015-4229

The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.

6.3AI Score

0.001EPSS

2015-06-30 10:59 AM
42
cve
cve

CVE-2015-4230

Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854.

6.9AI Score

0.003EPSS

2015-07-06 02:59 PM
28
cve
cve

CVE-2015-4231

The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

6.7AI Score

0.0004EPSS

2015-07-03 10:59 AM
27
cve
cve

CVE-2015-4232

Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

7.4AI Score

0.0004EPSS

2015-07-03 10:59 AM
25
cve
cve

CVE-2015-4233

SQL injection vulnerability in Cisco Unified MeetingPlace 8.6(1.2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu54037.

8.2AI Score

0.001EPSS

2015-07-02 10:59 AM
28
cve
cve

CVE-2015-4234

Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

6.7AI Score

0.0004EPSS

2015-07-03 10:59 AM
24
cve
cve

CVE-2015-4235

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to ...

6.5AI Score

0.002EPSS

2015-07-24 02:59 PM
32
cve
cve

CVE-2015-4236

Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.

6.9AI Score

0.003EPSS

2015-07-10 07:59 PM
40
cve
cve

CVE-2015-4237

The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv...

7.4AI Score

0.0004EPSS

2015-07-03 10:59 AM
36
cve
cve

CVE-2015-4238

The SNMP implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4(7) and 8.6(1.2) allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests during a time of high network traffic, aka Bug ID CSCul02601.

6.5AI Score

0.001EPSS

2015-07-02 02:59 PM
42
cve
cve

CVE-2015-4239

Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

6.7AI Score

0.001EPSS

2015-07-03 10:59 AM
39
cve
cve

CVE-2015-4240

Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified URL in a GET request, aka Bug ID CSCuu37656.

6.9AI Score

0.001EPSS

2015-07-08 02:59 PM
27
cve
cve

CVE-2015-4241

Cisco Adaptive Security Appliance (ASA) Software 9.3(2) allows remote attackers to cause a denial of service (system reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCut52679.

6.6AI Score

0.002EPSS

2015-07-08 02:59 PM
34
4
cve
cve

CVE-2015-4242

Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 5.4.1.2 and 6.0.0 in FireSIGHT Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu94721.

7.4AI Score

0.001EPSS

2015-07-08 02:59 PM
38
cve
cve

CVE-2015-4243

The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.

6.8AI Score

0.001EPSS

2015-07-08 02:59 PM
30
cve
cve

CVE-2015-4244

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.

7.6AI Score

0.0004EPSS

2015-07-10 10:59 AM
30
cve
cve

CVE-2015-4252

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence ISDN Gateway devices with software 2.2(1.106) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90724.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
26
cve
cve

CVE-2015-4253

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Serial Gateway devices with software 1.0(1.42) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90728.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
26
cve
cve

CVE-2015-4254

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Advanced Media Gateway devices with software 1.1(1.40) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90732.

7.6AI Score

0.001EPSS

2015-07-10 05:59 PM
30
cve
cve

CVE-2015-4255

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
32
cve
cve

CVE-2015-4256

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
24
cve
cve

CVE-2015-4257

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
40
cve
cve

CVE-2015-4258

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.

7.5AI Score

0.001EPSS

2015-07-10 12:59 AM
35
cve
cve

CVE-2015-4259

The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka ...

6.7AI Score

0.001EPSS

2015-07-10 03:59 PM
32
cve
cve

CVE-2015-4260

Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.

5.8AI Score

0.001EPSS

2015-07-10 10:59 AM
28
cve
cve

CVE-2015-4262

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

6.8AI Score

0.002EPSS

2015-07-24 02:59 PM
40
cve
cve

CVE-2015-4263

The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.

5.9AI Score

0.001EPSS

2015-07-10 07:59 PM
31
cve
cve

CVE-2015-4265

Cisco Unified Computing System (UCS) B Blade Server Software 2.2.x before 2.2.6 allows local users to cause a denial of service (host OS or BMC hang) by sending crafted packets over the Inter-IC (I2C) bus, aka Bug ID CSCuq77241.

6.5AI Score

0.0004EPSS

2015-10-12 10:59 AM
27
Total number of security vulnerabilities6090