Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2015-6354

Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338.

5.5AI Score

0.001EPSS

2015-10-31 04:59 AM
30
cve
cve

CVE-2015-6355

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.

6.5AI Score

0.002EPSS

2015-11-04 03:59 AM
32
cve
cve

CVE-2015-6356

Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.

5.9AI Score

0.001EPSS

2015-11-04 03:59 AM
26
cve
cve

CVE-2015-6357

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code...

7.1AI Score

0.003EPSS

2015-11-18 11:59 AM
29
cve
cve

CVE-2015-6358

Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installa...

5.9CVSS

5.9AI Score

0.003EPSS

2017-10-12 03:29 PM
152
cve
cve

CVE-2015-6359

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.

6.8AI Score

0.004EPSS

2015-12-15 05:59 AM
25
cve
cve

CVE-2015-6360

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

7.5CVSS

7.1AI Score

0.026EPSS

2016-04-21 10:59 AM
83
cve
cve

CVE-2015-6361

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

7.7AI Score

0.004EPSS

2015-12-13 03:59 AM
24
cve
cve

CVE-2015-6362

The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640.

6.5AI Score

0.001EPSS

2015-11-10 03:59 AM
26
cve
cve

CVE-2015-6363

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco FireSIGHT Management Center (MC) 5.4.1.4 and 6.0.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuw88396.

5.5AI Score

0.001EPSS

2015-11-12 03:59 AM
33
cve
cve

CVE-2015-6364

Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960.

6.3AI Score

0.003EPSS

2015-11-14 03:59 AM
24
cve
cve

CVE-2015-6365

Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.

6.4AI Score

0.001EPSS

2015-11-14 03:59 AM
43
cve
cve

CVE-2015-6366

Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended network-traffic restrictions in opportunistic circumstances by using a tunnel, aka Bug ID CSCur01042.

6.8AI Score

0.001EPSS

2015-11-13 03:59 AM
34
cve
cve

CVE-2015-6367

Cisco Aironet 1800 devices with software 8.1(131.0) allow remote attackers to cause a denial of service (CPU consumption) by improperly establishing many SSHv2 connections, aka Bug ID CSCux13374.

6.9AI Score

0.002EPSS

2015-11-14 03:59 AM
30
cve
cve

CVE-2015-6368

Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.

6.8AI Score

0.001EPSS

2015-11-19 02:59 AM
23
cve
cve

CVE-2015-6369

The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.

6.6AI Score

0.0004EPSS

2015-11-19 02:59 AM
36
cve
cve

CVE-2015-6370

The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.

7.5AI Score

0.0004EPSS

2015-11-19 02:59 AM
29
cve
cve

CVE-2015-6371

Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.

6.6AI Score

0.001EPSS

2015-11-19 02:59 AM
24
cve
cve

CVE-2015-6372

Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614.

5.8AI Score

0.001EPSS

2015-11-18 03:59 PM
25
cve
cve

CVE-2015-6373

Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611.

7.5AI Score

0.001EPSS

2015-11-18 03:59 PM
23
cve
cve

CVE-2015-6374

The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux1...

6.9AI Score

0.002EPSS

2015-11-19 02:59 AM
28
cve
cve

CVE-2015-6375

The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.

6AI Score

0.0004EPSS

2015-11-21 11:59 AM
30
cve
cve

CVE-2015-6376

Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412.

7.3AI Score

0.001EPSS

2015-11-21 11:59 AM
29
cve
cve

CVE-2015-6377

Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379.

6.8AI Score

0.002EPSS

2015-11-24 04:59 AM
24
cve
cve

CVE-2015-6378

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

7.5AI Score

0.001EPSS

2015-12-14 03:59 AM
24
cve
cve

CVE-2015-6379

The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.

6.3AI Score

0.001EPSS

2015-11-25 04:59 AM
25
cve
cve

CVE-2015-6380

An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.

7.5AI Score

0.004EPSS

2015-11-24 04:59 AM
22
cve
cve

CVE-2015-6382

Cisco ASR 5000 devices with software 16.0(900) allow remote attackers to cause a denial of service (telnetd process restart) via a TELNET connection, aka Bug ID CSCuv25815.

6.9AI Score

0.002EPSS

2015-11-26 03:59 AM
18
cve
cve

CVE-2015-6383

Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.

6.6AI Score

0.0004EPSS

2015-12-03 03:59 AM
32
cve
cve

CVE-2015-6384

The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.

6.6AI Score

0.002EPSS

2015-12-05 03:59 AM
27
cve
cve

CVE-2015-6385

The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943.

7.5AI Score

0.0004EPSS

2015-12-01 11:59 AM
26
cve
cve

CVE-2015-6386

The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.

6.9AI Score

0.002EPSS

2015-12-01 11:59 AM
29
cve
cve

CVE-2015-6387

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

5.8AI Score

0.001EPSS

2015-12-05 03:59 AM
25
cve
cve

CVE-2015-6388

Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575.

6.8AI Score

0.003EPSS

2015-12-05 03:59 AM
22
cve
cve

CVE-2015-6389

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.

6.8AI Score

0.006EPSS

2015-12-13 03:59 AM
25
cve
cve

CVE-2015-6390

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.

5.8AI Score

0.001EPSS

2015-12-03 03:59 AM
33
cve
cve

CVE-2015-6391

Cisco Unified SIP 3905 phones allow remote attackers to cause a denial of service (resource consumption and functionality loss) via a large amount of network traffic, aka Bug ID CSCuh51331.

6.8AI Score

0.002EPSS

2015-12-05 03:59 AM
22
cve
cve

CVE-2015-6392

Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via crafted IPv4 DHCP packets to the (1) DHCPv4 relay agent or (2) smart relay agent, aka Bug IDs CSCuq24603, CSC...

7.5CVSS

7.4AI Score

0.006EPSS

2016-10-06 01:59 AM
29
4
cve
cve

CVE-2015-6393

Cisco NX-OS 4.1 through 7.3 and 11.0 through 11.2 on Nexus 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device crash) via malformed IPv4 DHCP packets to the DHCPv4 relay agent, aka Bug IDs CSCuq39250, CSCus21733, CSCus2...

7.5CVSS

7.4AI Score

0.006EPSS

2016-10-06 10:59 AM
27
cve
cve

CVE-2015-6394

The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of service (device crash) via crafted USB parameters, aka Bug ID CSCus89408.

6.3AI Score

0.0004EPSS

2015-12-05 03:59 AM
32
cve
cve

CVE-2015-6395

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

6.8AI Score

0.002EPSS

2015-12-12 11:59 AM
30
cve
cve

CVE-2015-6396

The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

7.8CVSS

7.9AI Score

0.0004EPSS

2016-08-08 12:59 AM
61
cve
cve

CVE-2015-6397

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.

8.8CVSS

8.3AI Score

0.002EPSS

2016-08-08 12:59 AM
25
cve
cve

CVE-2015-6399

The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.

6.4AI Score

0.003EPSS

2015-12-15 05:59 AM
26
cve
cve

CVE-2015-6400

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.

5.9AI Score

0.001EPSS

2015-12-13 03:59 AM
36
cve
cve

CVE-2015-6401

Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.

7.8AI Score

0.003EPSS

2015-12-14 03:59 AM
29
cve
cve

CVE-2015-6402

Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.

6.8AI Score

0.002EPSS

2015-12-14 03:59 AM
41
cve
cve

CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.

6.4AI Score

0.0004EPSS

2015-12-15 05:59 AM
26
cve
cve

CVE-2015-6404

Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.

6AI Score

0.001EPSS

2015-12-15 05:59 AM
26
cve
cve

CVE-2015-6405

Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501.

7.4AI Score

0.002EPSS

2015-12-13 03:59 AM
27
Total number of security vulnerabilities6090