Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Secure Access Control System MEDIUM 6.5
CVE-2014-8027

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges fo…

Mitigation only
Fix from $1,600 2015-01-09
Meraki Mr Firmware HIGH 7.7
CVE-2014-7999

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unsp…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Meraki Mx Firmware HIGH 7.2
CVE-2014-7995

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Unified Communications Manager Im And Presence Service MEDIUM 5.0
CVE-2014-8000

Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user…

Mitigation only
Fix from $1,600 2014-11-21
iOS HIGH 7.1
CVE-2014-7998

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m…

Mitigation only
Fix from $1,950 2014-11-15
Asyncos MEDIUM 5.0
CVE-2014-3381

The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which …

Fix: after 8.5
Fix from $1,600 2014-10-19
Ios Xr HIGH 7.5
CVE-2014-3396

Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass…

Mitigation only
Fix from $1,950 2014-10-05
Transport Gateway Installation Software MEDIUM 5.0
CVE-2014-3345

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check …

Mitigation only
Fix from $1,600 2014-08-28
Nx Os MEDIUM 5.0
CVE-2014-3330

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-08-11
Unity Connection HIGH 9.0
CVE-2014-3333

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept…

Mitigation only
Fix from $1,950 2014-08-11
iOS MEDIUM 5.0
CVE-2014-3309

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows…

Mitigation only
Fix from $1,600 2014-07-09
Unified Cdm Application Software HIGH 7.5
CVE-2014-3300EPSS 22%

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not p…

Fix: after 8.1.4
Fix from $1,950 2014-07-07
Unified Cdm Application Software HIGH 9.0
CVE-2014-2197

The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 doe…

Fix: after 8.1
Fix from $1,950 2014-07-07
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3278

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack…

Mitigation only
Fix from $1,600 2014-06-08
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3281

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack…

Mitigation only
Fix from $1,600 2014-06-08
Webex Meetings Server MEDIUM 5.0
CVE-2014-3286

The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2014-06-08
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3279

The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implem…

Fix: after 9.0
Fix from $1,600 2014-05-29
Nx Os HIGH 7.1
CVE-2013-1191

Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…

Mitigation only
Fix from $1,950 2014-05-26
Nx Os HIGH 7.1
CVE-2014-2200

Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…

Mitigation only
Fix from $1,950 2014-05-26
Cisco Nexus 1000v Intercloud MEDIUM 5.0
CVE-2014-0685

Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2…

Fix: after 5.2
Fix from $1,600 2014-05-07
Telepresence Te Software HIGH 7.2
CVE-2014-2173

Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users t…

Mitigation only
Fix from $1,950 2014-05-02
iOS MEDIUM 5.0
CVE-2012-3946

Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an u…

Fix: after 15.3
Fix from $1,600 2014-04-24
Adaptive Security Appliance Software HIGH 8.5
CVE-2014-2126

Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 befor…

Mitigation only
Fix from $1,950 2014-04-10
Ironport Asyncos HIGH 8.5
CVE-2014-2119

The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1…

Fix: after 7.9.1-039
Fix from $1,950 2014-03-21
Unified Sip Phone 3905 HIGH 10.0
CVE-2014-0721

The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.8
CVE-2014-0719

The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denia…

Fix: after 7.1
Fix from $1,950 2014-02-22
Unified Communications Manager MEDIUM 5.0
CVE-2014-0731

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authenticatio…

Fix: after 10.0
Fix from $1,600 2014-02-22
Unified Communications Manager MEDIUM 6.0
CVE-2014-0686

Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file…

Fix: after 9.1
Fix from $1,600 2014-02-04
Secure Access Control System MEDIUM 5.5
CVE-2014-0678

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack…

Mitigation only
Fix from $1,600 2014-01-25
Nx Os MEDIUM 6.8
CVE-2014-0676

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

Mitigation only
Fix from $1,600 2014-01-22