Vulnerability index

Browse CVEs

221 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
iOS HIGH 7.5
CVE-2016-9201

A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass tra…

Mitigation only
Fix from $1,950 2016-12-14
Firesight System Software MEDIUM 6.5
CVE-2016-6471

A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authentic…

Mitigation only
Fix from $1,600 2016-12-14
Unified Communications Manager Im And Presence Service HIGH 7.5
CVE-2016-6464

A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, r…

Mitigation only
Fix from $1,950 2016-12-14
Meeting Server HIGH 7.5
CVE-2016-6446

A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. Mo…

Mitigation only
Fix from $1,950 2016-10-27
Secure Firewall Management Center MEDIUM 6.5
CVE-2016-6435EPSS 37%

The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug …

No fix yet
Fix from $1,600 2016-10-06
Nx Os HIGH 7.5
CVE-2016-1455

Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attacker…

Mitigation only
Fix from $1,950 2016-10-05
Firesight System Software MEDIUM 6.5
CVE-2016-6420

Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks …

Mitigation only
Fix from $1,600 2016-10-05
iOS HIGH 7.5
CVE-2016-6415 KEVEPSS 87%

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and…

Fix: 5.3.0+
Fix from $1,950 2016-09-19
iOS MEDIUM 5.3
CVE-2016-6398

The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2016-09-12
Small Business 220 Series Smart Plus Switches CRITICAL 9.8
CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…

Mitigation only
Fix from $2,300 2016-09-02
Unified Communications Manager HIGH 7.5
CVE-2016-6364

The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restri…

Mitigation only
Fix from $1,950 2016-08-23
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Connected Streaming Analytics MEDIUM 6.5
CVE-2016-1477

Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pag…

Mitigation only
Fix from $1,600 2016-08-23
Asr 5000 MEDIUM 6.5
CVE-2016-1452

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of th…

Mitigation only
Fix from $1,600 2016-07-15
Epc3928 Firmware HIGH 8.1
CVE-2016-1337

Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of…

No fix yet
Fix from $1,950 2016-07-03
Prime Network Registrar HIGH 7.5
CVE-2016-1427

The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…

Mitigation only
Fix from $1,950 2016-06-18
Ucs Invicta C3124sa Appliance HIGH 7.5
CVE-2016-1404

Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different …

Mitigation only
Fix from $1,950 2016-05-29
Webex Meeting Center HIGH 7.5
CVE-2016-1410

Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or …

Mitigation only
Fix from $1,950 2016-05-28
iOS MEDIUM 5.3
CVE-2016-1378

Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to…

Mitigation only
Fix from $1,600 2016-04-14
Prime Lan Management Solution HIGH 7.1
CVE-2016-1360

Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows…

Mitigation only
Fix from $1,950 2016-03-12
Dpc3939 Wireless Residential Voice Gateway Firmware HIGH 7.5
CVE-2016-1325

The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request…

Mitigation only
Fix from $1,950 2016-03-09
Cisco Policy Suite MEDIUM 5.3
CVE-2016-1357

The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote…

Mitigation only
Fix from $1,600 2016-03-03
Secure Firewall Management Center MEDIUM 5.3
CVE-2016-1342

The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2016-02-26
Universal Small Cell Firmware MEDIUM 5.8
CVE-2016-1321

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to…

Mitigation only
Fix from $1,600 2016-02-15
Telepresence Video Communication Server Software MEDIUM 5.3
CVE-2016-1316

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se…

Mitigation only
Fix from $1,600 2016-02-09
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2016-1295

Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt…

Mitigation only
Fix from $1,600 2016-01-16
Jabber MEDIUM 5.9
CVE-2015-6409

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMP…

Mitigation only
Fix from $1,600 2015-12-26
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter MEDIUM 5.0
CVE-2015-6428

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

Mitigation only
Fix from $1,600 2015-12-18
Secure Firewall Management Center MEDIUM 5.0
CVE-2015-6411

Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2015-12-15
Firesight System Software MEDIUM 6.8
CVE-2015-6419

Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via …

Mitigation only
Fix from $1,600 2015-12-12