Vulnerability index

Browse CVEs

1,018 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS HIGH 7.5
CVE-2016-1351

The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2016-03-26
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2016-1338

Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) vi…

Mitigation only
Fix from $1,600 2016-03-12
Prime Infrastructure HIGH 8.8
CVE-2016-1359

Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewi…

Mitigation only
Fix from $1,950 2016-03-03
Web Security Appliance MEDIUM 5.3
CVE-2016-1288

The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to…

Mitigation only
Fix from $1,600 2016-03-03
Small Business Wireless Access Points Firmware MEDIUM 5.3
CVE-2016-1334

Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request…

Mitigation only
Fix from $1,600 2016-02-17
500 Series Switch Firmware HIGH 7.5
CVE-2016-1303

The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID …

Mitigation only
Fix from $1,950 2016-01-30
Prime Network Services Controller HIGH 7.2
CVE-2015-6426

Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional p…

Mitigation only
Fix from $1,950 2015-12-18
Spa500 Firmware HIGH 7.2
CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows …

Mitigation only
Fix from $1,950 2015-12-15
Dpc3939 Wireless Residential Voice Gateway Firmware MEDIUM 6.5
CVE-2015-6361

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary com…

Mitigation only
Fix from $1,600 2015-12-13
iOS HIGH 7.2
CVE-2015-6385

The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbit…

Mitigation only
Fix from $1,950 2015-12-01
Firesight System Software MEDIUM 6.8
CVE-2015-6357

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire…

No fix yet
Fix from $1,600 2015-11-18
Email Security Appliance HIGH 7.8
CVE-2015-6291

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malfo…

Mitigation only
Fix from $1,950 2015-11-06
Asr 5000 Software MEDIUM 5.0
CVE-2015-6351

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-10-30
Asr 5000 Software MEDIUM 5.0
CVE-2015-6334

Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process rest…

Mitigation only
Fix from $1,600 2015-10-16
Telepresence Video Communication Server Software MEDIUM 6.9
CVE-2015-6318

Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified sy…

Mitigation only
Fix from $1,600 2015-10-12
iOS HIGH 7.8
CVE-2015-6279

The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE…

Mitigation only
Fix from $1,950 2015-09-28
iOS HIGH 7.8
CVE-2015-6278

The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE…

Mitigation only
Fix from $1,950 2015-09-28
Ios Xe HIGH 7.8
CVE-2015-6282

Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers t…

Mitigation only
Fix from $1,950 2015-09-26
Integrated Management Controller Supervisor HIGH 9.4
CVE-2015-6259

The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Uni…

Fix: after 5.2.0.0
Fix from $1,950 2015-09-04
Wireless Lan Controller Software MEDIUM 5.0
CVE-2015-6258

The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to …

Mitigation only
Fix from $1,600 2015-08-22
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-6256

Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fiel…

Mitigation only
Fix from $1,600 2015-08-22
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2015-4329

The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary …

Mitigation only
Fix from $1,600 2015-08-20
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2015-4321

The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(…

Mitigation only
Fix from $1,600 2015-08-20
Telepresence Video Communication Server Software MEDIUM 5.5
CVE-2015-4316

The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly va…

Mitigation only
Fix from $1,600 2015-08-20
Telepresence Video Communication Server Software HIGH 7.2
CVE-2015-4327

The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script argum…

Mitigation only
Fix from $1,950 2015-08-20
Telepresence Video Communication Server Software MEDIUM 5.5
CVE-2015-4315

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which…

Mitigation only
Fix from $1,600 2015-08-20
Unified Computing System Central Software MEDIUM 5.0
CVE-2015-4286

The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCu…

Mitigation only
Fix from $1,600 2015-07-29
Ios Xr MEDIUM 5.0
CVE-2015-4284

The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BG…

Mitigation only
Fix from $1,600 2015-07-22
Videoscape Distribution Suite Service Broker HIGH 7.8
CVE-2015-0725

Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Inte…

Patch available
Fix from $1,950 2015-07-16
Webex Meetings Server MEDIUM 6.5
CVE-2015-4276

Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.

Mitigation only
Fix from $1,600 2015-07-16