Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Asr 5000 Series Software MEDIUM 5.0
CVE-2014-0669

The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker…

Mitigation only
Fix from $1,600 2014-01-22
Secure Access Control System HIGH 10.0
CVE-2014-0648EPSS 6%

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System HIGH 9.0
CVE-2014-0649

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System MEDIUM 6.3
CVE-2014-0667

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated…

Mitigation only
Fix from $1,600 2014-01-16
Webex Training Center MEDIUM 5.0
CVE-2013-6965

The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem…

Mitigation only
Fix from $1,600 2013-12-14
Cloud Portal MEDIUM 5.0
CVE-2013-6708

Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889.

Mitigation only
Fix from $1,600 2013-12-10
Nexus 1000v MEDIUM 6.8
CVE-2013-5556

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.…

Fix: after 4.2
Fix from $1,600 2013-11-18
Server Provisioner MEDIUM 5.0
CVE-2013-3407

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allow…

Fix: after 6.4.0
Fix from $1,600 2013-11-18
Unified Ip Phone Firmware MEDIUM 6.6
CVE-2013-6685

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privile…

Mitigation only
Fix from $1,600 2013-11-13
iOS MEDIUM 6.4
CVE-2013-5552

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows…

Fix: after 12.4
Fix from $1,600 2013-11-13
iOS MEDIUM 6.8
CVE-2013-5522

Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service M…

Mitigation only
Fix from $1,600 2013-10-25
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5521

Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,600 2013-10-25
Unified Computing System MEDIUM 6.8
CVE-2012-4112

The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary command…

Mitigation only
Fix from $1,600 2013-10-19
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5538

The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary …

Mitigation only
Fix from $1,600 2013-10-16
Nx Os MEDIUM 6.8
CVE-2012-4121

Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, …

Mitigation only
Fix from $1,600 2013-10-14
Nx Os MEDIUM 6.8
CVE-2012-4077

Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651.

Mitigation only
Fix from $1,600 2013-10-14
Adaptive Security Appliance Software HIGH 10.0
CVE-2013-5509

The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypas…

Mitigation only
Fix from $1,950 2013-10-13
Firewall Services Module Software MEDIUM 6.6
CVE-2013-5506

The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context…

Mitigation only
Fix from $1,600 2013-10-13
Unified Computing System MEDIUM 6.8
CVE-2012-4106

The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows l…

Mitigation only
Fix from $1,600 2013-10-13
Nx Os MEDIUM 6.2
CVE-2012-4141

Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the…

Mitigation only
Fix from $1,600 2013-10-05
Unified Computing System MEDIUM 6.8
CVE-2012-4136

The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service…

Mitigation only
Fix from $1,600 2013-10-03
Unified Computing System MEDIUM 6.5
CVE-2012-1313

The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macs…

Mitigation only
Fix from $1,600 2013-09-27
Mediasense MEDIUM 5.0
CVE-2013-5502

The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2013-09-23
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2013-1130

Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a …

Mitigation only
Fix from $1,600 2013-09-20
Socialminer MEDIUM 5.0
CVE-2013-5489

The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2013-09-13
Unified Computing System MEDIUM 5.0
CVE-2013-1190

The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remot…

Mitigation only
Fix from $1,600 2013-08-02
Identity Services Engine MEDIUM 5.0
CVE-2013-3445

The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-07-29
Unified Meetingplace Web Conferencing MEDIUM 5.0
CVE-2013-3438

The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and rea…

No fix yet
Fix from $1,600 2013-07-24
iOS MEDIUM 5.0
CVE-2013-3436

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of…

Mitigation only
Fix from $1,600 2013-07-19
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify…

Mitigation only
Fix from $1,600 2013-07-18