Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2019-15288

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due to insufficient input...

8.8CVSS

8.9AI Score

0.002EPSS

2019-11-26 03:15 AM
92
cve
cve

CVE-2019-15289

Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to insufficient input validation....

7.5CVSS

7.5AI Score

0.002EPSS

2020-09-23 01:15 AM
55
cve
cve

CVE-2019-1585

A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device. The vulnerability is due to a misconfiguration of certain sudoers file...

7.8CVSS

7.5AI Score

0.0004EPSS

2019-03-06 09:29 PM
34
cve
cve

CVE-2019-1586

A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption keys stored on loca...

4.6CVSS

4.4AI Score

0.001EPSS

2019-05-03 03:29 PM
63
cve
cve

CVE-2019-1587

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly validate user-supplied input. An attack...

4.3CVSS

4.5AI Score

0.001EPSS

2019-05-03 03:29 PM
38
cve
cve

CVE-2019-1588

A vulnerability in the Cisco Nexus 9000 Series Fabric Switches running in Application-Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms o...

4.4CVSS

4.6AI Score

0.0004EPSS

2019-03-06 10:00 PM
33
cve
cve

CVE-2019-1589

A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive information on an affected device. The vu...

4.6CVSS

4.6AI Score

0.001EPSS

2019-05-03 03:29 PM
32
cve
cve

CVE-2019-1590

A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to perform insecure TLS client authentication on an affected device. Th...

8.1CVSS

8.4AI Score

0.002EPSS

2019-05-03 03:29 PM
52
cve
cve

CVE-2019-1591

A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insufficient sanitization of user-supplied input when issuing a s...

7.8CVSS

7.8AI Score

0.0004EPSS

2019-03-06 10:29 PM
35
cve
cve

CVE-2019-1592

A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affected device. The vulnerability is due to insufficient valida...

7.8CVSS

7.9AI Score

0.0004EPSS

2019-05-03 03:29 PM
40
cve
cve

CVE-2019-1593

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles. The attacker must authenticate with valid user credentials. The vulnerability is due to the ...

7.8CVSS

7.8AI Score

0.0004EPSS

2019-03-06 10:29 PM
44
cve
cve

CVE-2019-1594

A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incomplete input validation of Extensible Authentication Protocol over LAN (EAPOL) ...

7.4CVSS

7.4AI Score

0.001EPSS

2019-03-06 10:29 PM
41
cve
cve

CVE-2019-1595

A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an incorrect allocation of an internal interfac...

7.4CVSS

6.3AI Score

0.001EPSS

2019-03-06 10:29 PM
32
cve
cve

CVE-2019-15956

A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper authorization controls for a specific UR...

8.8CVSS

8.3AI Score

0.002EPSS

2019-11-26 03:15 AM
60
cve
cve

CVE-2019-15957

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system. When processed, the commands will be executed with ...

7.2CVSS

7.2AI Score

0.001EPSS

2020-09-23 01:15 AM
56
cve
cve

CVE-2019-15958

A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to insufficient input v...

9.8CVSS

9.8AI Score

0.006EPSS

2019-11-26 03:15 AM
58
cve
cve

CVE-2019-15959

A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit th...

6.6CVSS

6.7AI Score

0.0004EPSS

2020-09-23 01:15 AM
52
cve
cve

CVE-2019-1596

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level to root. The attacker must authenticate with valid user credentials. The vulnerability is due to incorrect permissions of a system executable. An ...

7.8CVSS

7.6AI Score

0.0004EPSS

2019-03-07 07:29 PM
34
cve
cve

CVE-2019-15960

A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is...

5.4CVSS

5.4AI Score

0.001EPSS

2019-11-26 03:15 AM
142
cve
cve

CVE-2019-15961

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in...

7.5CVSS

6.3AI Score

0.017EPSS

2020-01-15 07:15 PM
334
4
cve
cve

CVE-2019-15962

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit this vulnerability by...

4.4CVSS

4.6AI Score

0.0004EPSS

2019-10-16 07:15 PM
50
cve
cve

CVE-2019-15963

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-suppl...

6.5CVSS

6.4AI Score

0.001EPSS

2020-09-23 01:15 AM
46
cve
cve

CVE-2019-15966

A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation in the web application. An attacker could ex...

7.7CVSS

7.3AI Score

0.001EPSS

2019-11-05 07:15 PM
31
cve
cve

CVE-2019-15967

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users. The vulnerability is due to the presence of unnecessary debug commands. An attacker could exploit th...

4.4CVSS

4.5AI Score

0.0004EPSS

2019-11-26 03:15 AM
84
cve
cve

CVE-2019-15968

A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerabili...

5.4CVSS

5.2AI Score

0.001EPSS

2019-11-26 04:15 AM
75
cve
cve

CVE-2019-15969

A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability is due to insufficient validation of use...

6.1CVSS

6AI Score

0.002EPSS

2020-09-23 01:15 AM
58
cve
cve

CVE-2019-1597

Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vul...

8.6CVSS

7.6AI Score

0.002EPSS

2019-03-07 07:29 PM
48
cve
cve

CVE-2019-15971

A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file types. An attacker c...

4.3CVSS

4.7AI Score

0.001EPSS

2019-11-26 04:15 AM
72
cve
cve

CVE-2019-15972

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An...

8.8CVSS

8.8AI Score

0.001EPSS

2019-11-26 04:15 AM
75
cve
cve

CVE-2019-15973

A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected application. The vulnerability is due to insufficient valida...

6.1CVSS

5.9AI Score

0.002EPSS

2019-11-26 03:15 AM
64
cve
cve

CVE-2019-15974

A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vul...

6.1CVSS

6.2AI Score

0.001EPSS

2020-09-23 01:15 AM
86
cve
cve

CVE-2019-15975

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnera...

9.8CVSS

9.8AI Score

0.421EPSS

2020-01-06 08:15 AM
66
cve
cve

CVE-2019-15976

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnera...

9.8CVSS

9.8AI Score

0.967EPSS

2020-01-06 08:15 AM
64
cve
cve

CVE-2019-15977

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnera...

7.5CVSS

7.6AI Score

0.967EPSS

2020-01-06 08:15 AM
81
cve
cve

CVE-2019-15978

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information abo...

7.2CVSS

7.2AI Score

0.134EPSS

2020-01-06 08:15 AM
53
cve
cve

CVE-2019-15979

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information abo...

7.2CVSS

7.3AI Score

0.093EPSS

2020-01-06 08:15 AM
50
cve
cve

CVE-2019-1598

Multiple vulnerabilities in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vul...

8.6CVSS

7.5AI Score

0.002EPSS

2019-03-07 08:00 PM
41
cve
cve

CVE-2019-15980

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker wou...

7.2CVSS

7AI Score

0.163EPSS

2020-01-06 08:15 AM
35
cve
cve

CVE-2019-15981

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker wou...

7.2CVSS

7AI Score

0.163EPSS

2020-01-06 08:15 AM
32
cve
cve

CVE-2019-15982

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker wou...

7.2CVSS

7.1AI Score

0.163EPSS

2020-01-06 08:15 AM
32
cve
cve

CVE-2019-15983

A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application....

4.9CVSS

5.3AI Score

0.003EPSS

2020-01-06 08:15 AM
31
cve
cve

CVE-2019-15984

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DC...

7.2CVSS

7.9AI Score

0.347EPSS

2020-01-06 08:15 AM
59
cve
cve

CVE-2019-15985

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DC...

7.2CVSS

7.6AI Score

0.01EPSS

2020-01-06 08:15 AM
30
cve
cve

CVE-2019-15986

A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator credentials. The vulnerability is due to improper input valid...

6.7CVSS

6.7AI Score

0.0004EPSS

2019-11-26 04:15 AM
70
cve
cve

CVE-2019-15987

A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URL...

5.3CVSS

5.3AI Score

0.001EPSS

2019-11-26 04:15 AM
73
cve
cve

CVE-2019-15988

A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to insufficient input validation of URLs. An ...

5.3CVSS

5.3AI Score

0.001EPSS

2019-11-26 04:15 AM
85
cve
cve

CVE-2019-15989

A vulnerability in the implementation of the Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains a sp...

8.6CVSS

8.4AI Score

0.002EPSS

2020-01-26 05:15 AM
98
cve
cve

CVE-2019-1599

A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to an issue with allocating and freeing memory buffers in the network stack. An attacker could e...

8.6CVSS

8.4AI Score

0.001EPSS

2019-03-07 08:29 PM
41
cve
cve

CVE-2019-15990

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attack...

5.3CVSS

5.4AI Score

0.001EPSS

2019-11-26 04:15 AM
72
cve
cve

CVE-2019-15992

A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operatin...

7.2CVSS

7.2AI Score

0.002EPSS

2020-09-23 01:15 AM
59
Total number of security vulnerabilities6090