Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2015-6406

Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.

6.5AI Score

0.001EPSS

2015-12-13 03:59 AM
22
cve
cve

CVE-2015-6407

Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

7AI Score

0.001EPSS

2015-12-13 03:59 AM
28
cve
cve

CVE-2015-6408

Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux24578.

7.4AI Score

0.002EPSS

2015-12-12 04:59 PM
32
cve
cve

CVE-2015-6409

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.

5.9CVSS

5.6AI Score

0.001EPSS

2015-12-26 10:59 PM
29
cve
cve

CVE-2015-6410

The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setup restrictions by spoofing a user, aka Bug ID CSCuu97283.

7AI Score

0.001EPSS

2015-12-14 03:59 AM
22
cve
cve

CVE-2015-6411

Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.

6.5AI Score

0.002EPSS

2015-12-15 05:59 AM
26
cve
cve

CVE-2015-6412

Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.

9.8CVSS

9.3AI Score

0.004EPSS

2016-01-22 11:59 AM
23
cve
cve

CVE-2015-6413

Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.

6.5AI Score

0.001EPSS

2015-12-13 03:59 AM
28
cve
cve

CVE-2015-6414

Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.

6.4AI Score

0.0004EPSS

2015-12-13 03:59 AM
31
cve
cve

CVE-2015-6415

Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757.

7AI Score

0.006EPSS

2015-12-12 04:59 PM
24
cve
cve

CVE-2015-6416

Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479.

5.8AI Score

0.002EPSS

2015-12-14 03:59 AM
25
cve
cve

CVE-2015-6417

Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025.

6.4AI Score

0.001EPSS

2015-12-12 11:59 AM
23
cve
cve

CVE-2015-6418

The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224.

6.9AI Score

0.003EPSS

2015-12-13 03:59 AM
24
cve
cve

CVE-2015-6419

Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410.

6.4AI Score

0.001EPSS

2015-12-12 04:59 PM
30
cve
cve

CVE-2015-6421

cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device reload) via crafted network traffic, aka...

7.5CVSS

7.4AI Score

0.002EPSS

2016-01-27 10:59 PM
28
cve
cve

CVE-2015-6422

The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID CSCuu10981.

6.4AI Score

0.002EPSS

2015-12-14 03:59 AM
26
cve
cve

CVE-2015-6423

The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.

4.3CVSS

4.5AI Score

0.001EPSS

2016-01-15 03:59 AM
28
cve
cve

CVE-2015-6424

The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.

6.5AI Score

0.0004EPSS

2015-12-18 11:59 AM
32
cve
cve

CVE-2015-6425

The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.

6.8AI Score

0.006EPSS

2015-12-16 03:59 PM
29
cve
cve

CVE-2015-6426

Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CSCus99427.

7.4AI Score

0.0004EPSS

2015-12-18 11:59 AM
33
cve
cve

CVE-2015-6427

Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437.

6.9AI Score

0.001EPSS

2015-12-18 11:59 AM
36
cve
cve

CVE-2015-6428

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

6.3AI Score

0.001EPSS

2015-12-18 11:59 AM
24
cve
cve

CVE-2015-6429

The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.

6.6AI Score

0.002EPSS

2015-12-19 02:59 PM
32
cve
cve

CVE-2015-6431

Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.

6.5CVSS

6.3AI Score

0.004EPSS

2015-12-23 03:59 AM
29
cve
cve

CVE-2015-6432

Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCu...

7.5CVSS

7.3AI Score

0.002EPSS

2016-01-05 02:59 AM
29
cve
cve

CVE-2015-6433

SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.

6.5CVSS

6.8AI Score

0.001EPSS

2016-01-08 02:59 AM
32
cve
cve

CVE-2015-6434

Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.

6.1CVSS

4.9AI Score

0.001EPSS

2016-01-08 02:59 AM
34
cve
cve

CVE-2015-6435

An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur9088...

9.8CVSS

9.6AI Score

0.001EPSS

2016-01-22 11:59 AM
33
3
cve
cve

CVE-2015-7600

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

7AI Score

0.0004EPSS

2015-10-06 05:59 PM
38
cve
cve

CVE-2016-1287

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services ...

9.8CVSS

9.7AI Score

0.969EPSS

2016-02-11 06:59 PM
48
cve
cve

CVE-2016-1288

The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.

5.3CVSS

5.3AI Score

0.002EPSS

2016-03-03 10:59 PM
24
cve
cve

CVE-2016-1289

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CS...

9.8CVSS

9.5AI Score

0.011EPSS

2016-07-02 02:59 PM
29
cve
cve

CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.

8.1CVSS

7.8AI Score

0.001EPSS

2016-04-06 11:59 PM
24
cve
cve

CVE-2016-1291

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

9.8CVSS

9.6AI Score

0.047EPSS

2016-04-06 11:59 PM
30
cve
cve

CVE-2016-1293

Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414.

6.1CVSS

6AI Score

0.001EPSS

2016-01-16 05:59 AM
36
cve
cve

CVE-2016-1294

Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug ID CSCuw89094.

6.1CVSS

5.9AI Score

0.001EPSS

2016-01-16 05:59 AM
26
cve
cve

CVE-2016-1295

Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.

5.3CVSS

5.2AI Score

0.001EPSS

2016-01-16 05:59 AM
40
cve
cve

CVE-2016-1296

The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.

7.5CVSS

7.5AI Score

0.001EPSS

2016-01-20 05:59 AM
22
cve
cve

CVE-2016-1297

The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801.

8.8CVSS

8.7AI Score

0.004EPSS

2016-02-26 05:59 AM
33
cve
cve

CVE-2016-1298

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.

6.1CVSS

5.9AI Score

0.001EPSS

2016-01-26 05:59 AM
23
cve
cve

CVE-2016-1299

The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174.

5.3CVSS

5.3AI Score

0.001EPSS

2016-01-27 10:59 PM
29
cve
cve

CVE-2016-1300

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582.

6.1CVSS

5.9AI Score

0.001EPSS

2016-01-27 10:59 PM
26
cve
cve

CVE-2016-1301

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.

8.8CVSS

8.2AI Score

0.003EPSS

2016-02-07 11:59 AM
20
cve
cve

CVE-2016-1302

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST reques...

8.8CVSS

8.3AI Score

0.001EPSS

2016-02-07 11:59 AM
32
cve
cve

CVE-2016-1303

The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.

7.5CVSS

7.3AI Score

0.001EPSS

2016-01-30 12:59 PM
23
cve
cve

CVE-2016-1304

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux82596.

6.1CVSS

5.9AI Score

0.001EPSS

2016-01-30 12:59 PM
29
cve
cve

CVE-2016-1305

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511.

6.1CVSS

5.9AI Score

0.001EPSS

2016-02-07 11:59 AM
26
cve
cve

CVE-2016-1309

Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy01843.

6.1CVSS

6AI Score

0.001EPSS

2016-02-07 11:59 AM
28
cve
cve

CVE-2016-1311

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224.

6.1CVSS

6AI Score

0.001EPSS

2016-02-06 05:59 AM
20
cve
cve

CVE-2016-1312

The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of HTTPS packets, aka Bug ID CSCue76147.

7.5CVSS

7.4AI Score

0.005EPSS

2016-03-09 08:59 PM
25
Total number of security vulnerabilities6090