Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Virtualization Experience Client 6000 Series Firmware MEDIUM 6.8
CVE-2013-3408

The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain pri…

Mitigation only
Fix from $1,600 2013-07-10
Telepresence Tc Software HIGH 8.3
CVE-2013-3379

The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote…

Fix: after 4.1.2
Fix from $1,950 2013-06-21
Unified Customer Voice Portal HIGH 7.8
CVE-2013-1225

Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP…

Fix: after 9.0
Fix from $1,950 2013-05-09
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2013-1215

The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via un…

Mitigation only
Fix from $1,600 2013-04-25
Unified Computing System Infrastructure And Unified Computing System Software HIGH 9.3
CVE-2013-1182

The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) all…

Fix: after 1.0
Fix from $1,950 2013-04-25
Firewall Services Module MEDIUM 5.0
CVE-2013-1195

The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properl…

Mitigation only
Fix from $1,600 2013-04-24
Unified Contact Center Express Editor Software MEDIUM 5.0
CVE-2013-1214

The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows r…

Mitigation only
Fix from $1,600 2013-04-24
Unified Meetingplace Web Conferencing Server HIGH 9.3
CVE-2013-1169

Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Reme…

Mitigation only
Fix from $1,950 2013-04-11
Ata 187 Analog Telephone Adaptor Firmware HIGH 9.0
CVE-2013-1111

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allo…

Mitigation only
Fix from $1,950 2013-02-13
Wireless Lan Controller Software HIGH 9.0
CVE-2013-1105

Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote a…

Mitigation only
Fix from $1,950 2013-01-24
Adaptive Security Appliance Software MEDIUM 6.3
CVE-2012-5717

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authentica…

Mitigation only
Fix from $1,600 2013-01-18
Telepresence Video Communication Servers Software MEDIUM 5.0
CVE-2012-5444

Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create co…

Mitigation only
Fix from $1,600 2013-01-17
Prime Data Center Network Manager HIGH 10.0
CVE-2012-5417

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which all…

Mitigation only
Fix from $1,950 2012-11-02
Ip Communicator MEDIUM 5.0
CVE-2012-0361

The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications …

Mitigation only
Fix from $1,600 2012-05-02
Wireless Lan Controller Software HIGH 9.3
CVE-2012-0371

Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote atta…

Mitigation only
Fix from $1,950 2012-03-01
Unity Connection HIGH 9.0
CVE-2012-0366

Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Adminis…

Fix: after 7.1
Fix from $1,950 2012-03-01
Small Business Srp520 Series Firmware HIGH 7.8
CVE-2012-0364

Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to r…

Fix: after 1.01.24
Fix from $1,950 2012-02-25
Telepresence E20 Software HIGH 10.0
CVE-2011-4659

Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0,…

Mitigation only
Fix from $1,950 2012-01-19
Nx Os MEDIUM 6.8
CVE-2011-2569

Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, wh…

Mitigation only
Fix from $1,600 2011-10-27
Show And Share HIGH 7.5
CVE-2011-2584

Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Co…

Fix: after 5.2
Fix from $1,950 2011-10-20
Nx Os MEDIUM 5.0
CVE-2011-2581

The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000…

Fix: after 5.0
Fix from $1,600 2011-09-14
Sa500 Software HIGH 9.0
CVE-2011-2547

The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execut…

Fix: after 2.1.18
Fix from $1,950 2011-07-28
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2011-2041

The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and…

Fix: after 2.3.2016
Fix from $1,950 2011-06-02
Unified Ip Phone 7906 MEDIUM 6.6
CVE-2011-1602

The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif…

Mitigation only
Fix from $1,600 2011-06-02
Unified Ip Phone 7906 MEDIUM 6.6
CVE-2011-1603

Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bu…

Mitigation only
Fix from $1,600 2011-06-02
Nac Guest Server MEDIUM 5.0
CVE-2011-0963

The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 a…

Fix: after 2.0.2
Fix from $1,600 2011-03-31
Adaptive Security Appliance HIGH 7.8
CVE-2011-0396

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 b…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Multipoint Switch Software HIGH 8.0
CVE-2011-0387

The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote au…

Mitigation only
Fix from $1,950 2011-02-25
iOS MEDIUM 6.4
CVE-2011-0348

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on …

Mitigation only
Fix from $1,600 2011-01-28
Adaptive Security Appliance Software HIGH 7.8
CVE-2010-4689

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, whi…

Fix: after 8.3
Fix from $1,950 2011-01-07