Vulnerability index

Browse CVEs

323 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nx Os CRITICAL 9.8
CVE-2016-1453EPSS 8%

Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote…

Mitigation only
Fix from $2,300 2016-10-06
Email Security Appliance Firmware CRITICAL 9.8
CVE-2016-6406

Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)…

Mitigation only
Fix from $2,300 2016-09-22
Cloud Services Platform 2100 CRITICAL 9.8
CVE-2016-6374

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…

Mitigation only
Fix from $2,300 2016-09-22
Firesight System Software CRITICAL 9.1
CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…

Mitigation only
Fix from $2,300 2016-09-12
Small Business 220 Series Smart Plus Switches CRITICAL 9.8
CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…

Mitigation only
Fix from $2,300 2016-09-02
Prime Collaboration Provisioning CRITICAL 9.8
CVE-2016-1416

Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administra…

Mitigation only
Fix from $2,300 2016-07-02
Prime Infrastructure CRITICAL 9.8
CVE-2016-1289EPSS 5%

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrar…

Mitigation only
Fix from $2,300 2016-07-02
Rv130w Wireless N Multifunction Vpn Router Firmware CRITICAL 9.8
CVE-2016-1395

The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W dev…

Mitigation only
Fix from $2,300 2016-06-19
Network Analysis Module CRITICAL 9.8
CVE-2016-1388

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) be…

Mitigation only
Fix from $2,300 2016-06-03
Telepresence Tc Software CRITICAL 9.8
CVE-2016-1387

The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8…

Mitigation only
Fix from $2,300 2016-05-05
Information Server CRITICAL 10.0
CVE-2016-1343

The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory con…

Mitigation only
Fix from $2,300 2016-04-30
Wireless Lan Controller Software CRITICAL 9.8
CVE-2016-1363EPSS 6%

Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through…

Fix: 7.4.140.0 / 8.0.115.0+
Fix from $2,300 2016-04-21
Unified Computing System Central Software CRITICAL 9.8
CVE-2016-1352

Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP…

Mitigation only
Fix from $2,300 2016-04-14
Ucs Invicta C3124sa Appliance CRITICAL 9.8
CVE-2016-1313

Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default…

Mitigation only
Fix from $2,300 2016-04-06
Evolved Programmable Network Manager CRITICAL 9.8
CVE-2016-1291EPSS 5%

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2016-04-06
Dpc2203 Cable Modem Firmware CRITICAL 9.8
CVE-2016-1327EPSS 6%

Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2016-03-09
Nx Os CRITICAL 9.8
CVE-2016-1341

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…

Mitigation only
Fix from $2,300 2016-02-24
Adaptive Security Appliance Software CRITICAL 9.8
CVE-2016-1287EPSS 53%

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before…

No fix yet
Fix from $2,300 2016-02-11
Rv Series Router Firmware CRITICAL 9.8
CVE-2015-6319

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands v…

Mitigation only
Fix from $2,300 2016-01-27
Firepower Extensible Operating System CRITICAL 9.8
CVE-2015-6435EPSS 7%

An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(…

No fix yet
Fix from $2,300 2016-01-22
Modular Encoding Platform D9036 Software CRITICAL 9.8
CVE-2015-6412

Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attac…

Mitigation only
Fix from $2,300 2016-01-22
Identity Services Engine Software CRITICAL 9.8
CVE-2015-6323

The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch…

Mitigation only
Fix from $2,300 2016-01-15
Wireless Lan Controller Software CRITICAL 9.8
CVE-2015-6314

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…

Mitigation only
Fix from $2,300 2016-01-15