Vulnerability index

Browse CVEs

300 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2014-0669 The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker… Asr 5000 Series Software Mitigation only Fix from $1,6002014-01-22 HIGH 10.0 CVE-2014-0648EPSS 6% The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,… Secure Access Control System after 5.4.0.46.6 Fix from $1,9502014-01-16 HIGH 9.0 CVE-2014-0649 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot… Secure Access Control System after 5.4.0.46.6 Fix from $1,9502014-01-16 MEDIUM 6.3 CVE-2014-0667 The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated… Secure Access Control System Mitigation only Fix from $1,6002014-01-16 MEDIUM 5.0 CVE-2013-6965 The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6708 Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889. Cloud Portal Mitigation only Fix from $1,6002013-12-10 MEDIUM 6.8 CVE-2013-5556 The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.… Nexus 1000v after 4.2 Fix from $1,6002013-11-18 MEDIUM 5.0 CVE-2013-3407 The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allow… Server Provisioner after 6.4.0 Fix from $1,6002013-11-18 MEDIUM 6.6 CVE-2013-6685 The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privile… Unified Ip Phone Firmware Mitigation only Fix from $1,6002013-11-13 MEDIUM 6.4 CVE-2013-5552 Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows… iOS after 12.4 Fix from $1,6002013-11-13 MEDIUM 6.8 CVE-2013-5522 Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service M… iOS Mitigation only Fix from $1,6002013-10-25 MEDIUM 5.0 CVE-2013-5521 Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service … Identity Services Engine Software Mitigation only Fix from $1,6002013-10-25 MEDIUM 6.8 CVE-2012-4112 The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary command… Unified Computing System Mitigation only Fix from $1,6002013-10-19 MEDIUM 5.0 CVE-2013-5538 The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary … Identity Services Engine Software Mitigation only Fix from $1,6002013-10-16 MEDIUM 6.8 CVE-2012-4121 Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, … Nx Os Mitigation only Fix from $1,6002013-10-14 MEDIUM 6.8 CVE-2012-4077 Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651. Nx Os Mitigation only Fix from $1,6002013-10-14 HIGH 10.0 CVE-2013-5509 The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypas… Adaptive Security Appliance Software Mitigation only Fix from $1,9502013-10-13 MEDIUM 6.6 CVE-2013-5506 The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context… Firewall Services Module Software Mitigation only Fix from $1,6002013-10-13 MEDIUM 6.8 CVE-2012-4106 The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows l… Unified Computing System Mitigation only Fix from $1,6002013-10-13 MEDIUM 6.2 CVE-2012-4141 Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the… Nx Os Mitigation only Fix from $1,6002013-10-05 MEDIUM 6.8 CVE-2012-4136 The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service… Unified Computing System Mitigation only Fix from $1,6002013-10-03 MEDIUM 6.5 CVE-2012-1313 The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macs… Unified Computing System Mitigation only Fix from $1,6002013-09-27 MEDIUM 5.0 CVE-2013-5502 The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sens… Mediasense Mitigation only Fix from $1,6002013-09-23 MEDIUM 6.8 CVE-2013-1130 Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a … Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002013-09-20 MEDIUM 5.0 CVE-2013-5489 The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensit… Socialminer Mitigation only Fix from $1,6002013-09-13 MEDIUM 5.0 CVE-2013-1190 The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remot… Unified Computing System Mitigation only Fix from $1,6002013-08-02 MEDIUM 5.0 CVE-2013-3445 The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of ser… Identity Services Engine Mitigation only Fix from $1,6002013-07-29 MEDIUM 5.0 CVE-2013-3438 The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and rea… Unified Meetingplace Web Conferencing No fix yet Fix from $1,6002013-07-24 MEDIUM 5.0 CVE-2013-3436 The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of… iOS Mitigation only Fix from $1,6002013-07-19 MEDIUM 5.0 CVE-2013-3426 The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify… Unified Ip Phones 9900 Series Firmware Mitigation only Fix from $1,6002013-07-18