Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.6 CVE-2015-6322 The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move… Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002015-10-12 MEDIUM 6.9 CVE-2015-4325 The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges … Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-10-12 HIGH 7.2 CVE-2015-7600 Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrar… Vpn Client No fix yet Fix from $1,9502015-10-06 HIGH 7.2 CVE-2015-6306 Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to o… Anyconnect Secure Mobility Client Patch available Fix from $1,9502015-09-26 HIGH 9.0 CVE-2015-4307 The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and … Prime Collaboration Provisioning Mitigation only Fix from $1,9502015-09-20 HIGH 8.5 CVE-2015-4306 The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session rea… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-09-20 HIGH 9.0 CVE-2015-4304 The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictio… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-09-20 HIGH 7.2 CVE-2015-6296 Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging… Prime Network Registrar Mitigation only Fix from $1,9502015-09-18 MEDIUM 6.5 CVE-2015-4303 Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobo… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-08-20 MEDIUM 5.5 CVE-2015-4322 Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authent… Content Security Management Appliance Mitigation only Fix from $1,6002015-08-19 MEDIUM 5.0 CVE-2015-4287 Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and ob… Firepower Extensible Operating System Mitigation only Fix from $1,6002015-07-29 HIGH 9.0 CVE-2015-4235 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with… Application Policy Infrastructure Controller \(apic\) Mitigation only Fix from $1,9502015-07-24 HIGH 7.2 CVE-2015-4234 Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input… Nx Os Mitigation only Fix from $1,9502015-07-03 HIGH 7.2 CVE-2015-4211 Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a cr… Anyconnect Secure Mobility Client Mitigation only Fix from $1,9502015-06-24 MEDIUM 6.9 CVE-2015-4185 The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session ver… iOS Mitigation only Fix from $1,6002015-06-13 MEDIUM 5.5 CVE-2015-4182 The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restr… Identity Services Engine Software Mitigation only Fix from $1,6002015-06-12 MEDIUM 6.5 CVE-2015-0768 The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implem… Prime Network Control System Mitigation only Fix from $1,6002015-06-12 MEDIUM 5.5 CVE-2015-0773 Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deleti… Firesight System Software Mitigation only Fix from $1,6002015-06-12 HIGH 7.2 CVE-2015-0767 Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified commands, aka Bug ID CSCur18132. Edge 340 Firmware Mitigation only Fix from $1,9502015-06-07 HIGH 7.2 CVE-2015-0761 Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions… Anyconnect Secure Mobility Client after 3.1 Fix from $1,9502015-06-04 HIGH 9.0 CVE-2015-0713 The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco… Telepresence Advanced Media Gateway Mitigation only Fix from $1,9502015-05-25 MEDIUM 6.5 CVE-2015-0750 The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitr… Hosted Collaboration Solution Mitigation only Fix from $1,6002015-05-23 MEDIUM 6.9 CVE-2015-0717 Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug… Unified Communications Manager Mitigation only Fix from $1,6002015-05-16 HIGH 9.3 CVE-2015-0691 A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a … Secure Desktop Mitigation only Fix from $1,9502015-04-17 HIGH 7.2 CVE-2015-0692 Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel… Web Security Appliance Mitigation only Fix from $1,9502015-04-11 MEDIUM 6.5 CVE-2015-0682 Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka B… Unified Communications Domain Manager Mitigation only Fix from $1,6002015-04-03 MEDIUM 6.6 CVE-2015-0663 Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users… Anyconnect Secure Mobility Client after 4.0 Fix from $1,6002015-03-17 HIGH 7.2 CVE-2015-0662 Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of ro… Anyconnect Secure Mobility Client after 4.0 Fix from $1,9502015-03-17 MEDIUM 6.5 CVE-2014-2130 Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authentic… Secure Access Control System Mitigation only Fix from $1,6002015-03-06 MEDIUM 6.5 CVE-2015-0611 The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-… Telepresence System Software Ix Mitigation only Fix from $1,6002015-02-12