58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
Cisco vulnerabilities
6716 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-6422 | HIGH 7.5 | cisco ios Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM share ACLs, which allows remote attackers to bypass intended access restrictions by sending packets that should h | 1.5% | — |
| CVE-2012-1342 | MED 5.8 | cisco carrier_routing_system Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975. | 1.5% | — |
| CVE-2017-6689 | HIGH 8.8 | cisco elastic_services_controller A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. More Information: CSCvc7666 | 1.5% | — |
| CVE-2017-6687 | HIGH 8.8 | cisco ultra_services_framework_element_manager A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Pass | 1.5% | — |
| CVE-2017-6686 | HIGH 8.8 | cisco ultra_services_framework_element_manager A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. | 1.5% | — |
| CVE-2017-6685 | HIGH 8.8 | cisco ultra_services_framework_staging_server A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More Info | 1.5% | — |
| CVE-2015-4263 | MED 4.0 | cisco mobility_services_engine The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851. | 1.5% | — |
| CVE-2014-8010 | MED 6.5 | cisco unified_communications_domain_manager The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205. | 1.5% | — |
| CVE-2008-1743 | HIGH 7.8 | cisco unified_communications_manager Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a ser | 1.5% | — |
| CVE-2002-0870 | HIGH 7.5 | cisco content_services_switch_11000 The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of | 1.5% | — |
| CVE-2015-0598 | MED 6.8 | cisco ios The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted IPv6 Attributes in Access-Accept packets, aka Bug IDs CSCur84322 and CSCur27693. | 1.5% | — |
| CVE-2014-3269 | MED 6.8 | cisco ios_xe The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204. | 1.5% | — |
| CVE-2013-6686 | MED 6.8 | cisco ios The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568. | 1.5% | — |
| CVE-2015-0671 | MED 5.0 | cisco videoscape_delivery_system_for_internet_streamer The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911. | 1.5% | — |
| CVE-2013-5536 | MED 5.0 | cisco secure_access_control_system Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) via a flood of crafted packets, aka Bug ID CSCui51521. | 1.5% | — |
| CVE-2013-1190 | MED 5.0 | cisco unified_computing_system The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets, | 1.5% | — |
| CVE-2012-3913 | MED 5.0 | cisco vc240_network_bullet_camera The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019. | 1.5% | — |
| CVE-2013-1138 | MED 5.0 | cisco adaptive_security_appliance The NAT process on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (connections-table memory consumption) via crafted packets, aka Bug ID CSCue46386. | 1.5% | — |
| CVE-2022-20683 | HIGH 8.6 | cisco ios_xe A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected | 1.5% | — |
| CVE-2019-12710 | MED 4.9 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by ex | 1.5% | — |
| CVE-2019-1977 | MED 6.8 | cisco nx-os A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device | 1.5% | — |
| CVE-2021-1446 | HIGH 8.6 | cisco ios_xe A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a log | 1.5% | — |
| CVE-2021-1437 | HIGH 7.5 | cisco aironet_access_point_software A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial F | 1.5% | — |
| CVE-2020-3444 | HIGH 7.5 | cisco ios_xe A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker | 1.5% | — |
| CVE-2021-1373 | HIGH 8.6 | cisco ios_xe A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause | 1.5% | — |