Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Application Policy Infrastructure Controller HIGH 7.8
CVE-2016-6413

The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local u…

Mitigation only
Fix from $1,950 2016-09-24
Email Security Appliance Firmware CRITICAL 9.8
CVE-2016-6406

Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)…

Mitigation only
Fix from $2,300 2016-09-22
Unified Computing System HIGH 7.8
CVE-2016-6402

UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via …

Mitigation only
Fix from $1,950 2016-09-18
Firesight System Software CRITICAL 9.1
CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…

Mitigation only
Fix from $2,300 2016-09-12
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2016-6369

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges…

Mitigation only
Fix from $1,950 2016-08-25
Aironet Access Point Software HIGH 7.8
CVE-2016-6362

Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to …

Mitigation only
Fix from $1,950 2016-08-22
Secure Firewall Management Center HIGH 8.8
CVE-2016-1458

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptiv…

Mitigation only
Fix from $1,950 2016-08-18
Secure Firewall Management Center HIGH 8.8
CVE-2016-1457

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA…

Mitigation only
Fix from $1,950 2016-08-18
Ios Xr HIGH 7.8
CVE-2016-1456

The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified conta…

Mitigation only
Fix from $1,950 2016-07-15
Epc3928 Firmware HIGH 8.1
CVE-2016-1337

Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of…

No fix yet
Fix from $1,950 2016-07-03
Firesight System Software HIGH 8.6
CVE-2016-1394

Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowled…

Mitigation only
Fix from $1,950 2016-07-03
Prime Collaboration Provisioning CRITICAL 9.8
CVE-2016-1416

Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administra…

Mitigation only
Fix from $2,300 2016-07-02
Ip Phone 8800 Series Firmware HIGH 7.0
CVE-2016-1435

Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files …

Mitigation only
Fix from $1,950 2016-06-23
Application Policy Infrastructure Controller Enterprise Module HIGH 7.5
CVE-2016-1386

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative noti…

Mitigation only
Fix from $1,950 2016-04-28
iOS HIGH 7.5
CVE-2016-1384

The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, …

Mitigation only
Fix from $1,950 2016-04-20
Ucs Invicta C3124sa Appliance CRITICAL 9.8
CVE-2016-1313

Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default…

Mitigation only
Fix from $2,300 2016-04-06
Evolved Programmable Network Manager HIGH 8.1
CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated …

Mitigation only
Fix from $1,950 2016-04-06
Ios Xr MEDIUM 6.5
CVE-2016-1366

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which …

Mitigation only
Fix from $1,600 2016-03-24
Nx Os CRITICAL 9.8
CVE-2016-1341

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…

Mitigation only
Fix from $2,300 2016-02-24
Asr 5000 Series Software HIGH 7.5
CVE-2016-1335

The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key auth…

Mitigation only
Fix from $1,950 2016-02-19
Spark MEDIUM 5.3
CVE-2016-1324

The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page,…

Mitigation only
Fix from $1,600 2016-02-12
Spark HIGH 7.5
CVE-2016-1322

The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via un…

Mitigation only
Fix from $1,950 2016-02-12
Prime Collaboration MEDIUM 6.7
CVE-2016-1320

The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges,…

Mitigation only
Fix from $1,600 2016-02-12
Videoscape Distribution Suite Service Manager MEDIUM 6.5
CVE-2015-6417

Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows rem…

Mitigation only
Fix from $1,600 2015-12-12
Prime Service Catalog MEDIUM 6.5
CVE-2015-6395

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify th…

Mitigation only
Fix from $1,600 2015-12-12
Ios Xe HIGH 7.2
CVE-2015-6383

Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain cert…

Mitigation only
Fix from $1,950 2015-12-03
Mobility Services Engine MEDIUM 6.9
CVE-2015-4282

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root pr…

Mitigation only
Fix from $1,600 2015-11-06
Wireless Lan Controller Software MEDIUM 5.0
CVE-2015-6341

The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-10-25
Firesight System Software HIGH 9.0
CVE-2015-6335

The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to b…

Mitigation only
Fix from $1,950 2015-10-25
Aironet Access Point Software HIGH 7.2
CVE-2015-6315

Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.

Mitigation only
Fix from $1,950 2015-10-13