Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2015-6322

The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move…

Mitigation only
Fix from $1,600 2015-10-12
Telepresence Video Communication Server Software MEDIUM 6.9
CVE-2015-4325

The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges …

Mitigation only
Fix from $1,600 2015-10-12
Vpn Client HIGH 7.2
CVE-2015-7600

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrar…

No fix yet
Fix from $1,950 2015-10-06
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-6306

Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to o…

Patch available
Fix from $1,950 2015-09-26
Prime Collaboration Provisioning HIGH 9.0
CVE-2015-4307

The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and …

Mitigation only
Fix from $1,950 2015-09-20
Prime Collaboration Assurance HIGH 8.5
CVE-2015-4306

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session rea…

Mitigation only
Fix from $1,950 2015-09-20
Prime Collaboration Assurance HIGH 9.0
CVE-2015-4304

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictio…

Mitigation only
Fix from $1,950 2015-09-20
Prime Network Registrar HIGH 7.2
CVE-2015-6296

Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging…

Mitigation only
Fix from $1,950 2015-09-18
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2015-4303

Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobo…

Mitigation only
Fix from $1,600 2015-08-20
Content Security Management Appliance MEDIUM 5.5
CVE-2015-4322

Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authent…

Mitigation only
Fix from $1,600 2015-08-19
Firepower Extensible Operating System MEDIUM 5.0
CVE-2015-4287

Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and ob…

Mitigation only
Fix from $1,600 2015-07-29
Application Policy Infrastructure Controller \(apic\) HIGH 9.0
CVE-2015-4235

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with…

Mitigation only
Fix from $1,950 2015-07-24
Nx Os HIGH 7.2
CVE-2015-4234

Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input…

Mitigation only
Fix from $1,950 2015-07-03
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-4211

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a cr…

Mitigation only
Fix from $1,950 2015-06-24
iOS MEDIUM 6.9
CVE-2015-4185

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session ver…

Mitigation only
Fix from $1,600 2015-06-13
Identity Services Engine Software MEDIUM 5.5
CVE-2015-4182

The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restr…

Mitigation only
Fix from $1,600 2015-06-12
Prime Network Control System MEDIUM 6.5
CVE-2015-0768

The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implem…

Mitigation only
Fix from $1,600 2015-06-12
Firesight System Software MEDIUM 5.5
CVE-2015-0773

Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deleti…

Mitigation only
Fix from $1,600 2015-06-12
Edge 340 Firmware HIGH 7.2
CVE-2015-0767

Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified commands, aka Bug ID CSCur18132.

Mitigation only
Fix from $1,950 2015-06-07
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-0761

Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions…

Fix: after 3.1
Fix from $1,950 2015-06-04
Telepresence Advanced Media Gateway HIGH 9.0
CVE-2015-0713

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco…

Mitigation only
Fix from $1,950 2015-05-25
Hosted Collaboration Solution MEDIUM 6.5
CVE-2015-0750

The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitr…

Mitigation only
Fix from $1,600 2015-05-23
Unified Communications Manager MEDIUM 6.9
CVE-2015-0717

Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug…

Mitigation only
Fix from $1,600 2015-05-16
Secure Desktop HIGH 9.3
CVE-2015-0691

A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a …

Mitigation only
Fix from $1,950 2015-04-17
Web Security Appliance HIGH 7.2
CVE-2015-0692

Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel…

Mitigation only
Fix from $1,950 2015-04-11
Unified Communications Domain Manager MEDIUM 6.5
CVE-2015-0682

Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka B…

Mitigation only
Fix from $1,600 2015-04-03
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2015-0663

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users…

Fix: after 4.0
Fix from $1,600 2015-03-17
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-0662

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of ro…

Fix: after 4.0
Fix from $1,950 2015-03-17
Secure Access Control System MEDIUM 6.5
CVE-2014-2130

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authentic…

Mitigation only
Fix from $1,600 2015-03-06
Telepresence System Software Ix MEDIUM 6.5
CVE-2015-0611

The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-…

Mitigation only
Fix from $1,600 2015-02-12