Vulnerability index

Browse CVEs

129 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ios Xe MEDIUM 5.3
CVE-2019-1759

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unaut…

Patch available
Fix from $1,600 2019-03-28
Ip Phone 8821 Firmware HIGH 7.5
CVE-2019-1763

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una…

Fix: 11.0 / 12.5+
Fix from $1,950 2019-03-22
Application Policy Infrastructure Controller MEDIUM 6.5
CVE-2019-1690

A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adj…

Fix: 4.2+
Fix from $1,600 2019-03-11
Nx Os HIGH 7.8
CVE-2019-1601

A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a…

Fix: 6.0 / 6.2+
Fix from $1,950 2019-03-08
Hyperflex Hx Data Platform HIGH 7.8
CVE-2019-1664

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in …

Mitigation only
Fix from $1,950 2019-02-21
Hyperflex Hx Data Platform MEDIUM 5.3
CVE-2019-1666

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphit…

Mitigation only
Fix from $1,600 2019-02-21
Telepresence Management Suite MEDIUM 5.3
CVE-2019-1660

A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, rem…

Mitigation only
Fix from $1,600 2019-02-07
Rv320 Firmware HIGH 7.5
CVE-2019-1653 KEVEPSS 100%

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic…

Mitigation only
Fix from $1,950 2019-01-24
Sd Wan HIGH 8.0
CVE-2019-1647

A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized ac…

Fix: 18.4.0+
Fix from $1,950 2019-01-24
Identity Services Engine HIGH 7.2
CVE-2018-15459

A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain add…

Mitigation only
Fix from $1,950 2019-01-23
iOS MEDIUM 6.5
CVE-2018-0484

A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a vi…

Mitigation only
Fix from $1,600 2019-01-10
Stealthwatch Enterprise CRITICAL 9.8
CVE-2018-15394

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypa…

Fix: after 6.10.2
Fix from $2,300 2018-11-08
Wireless Lan Controller Software MEDIUM 5.4
CVE-2018-15395

A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authentica…

Mitigation only
Fix from $1,600 2018-10-17
Ios Xe HIGH 8.1
CVE-2018-15372

A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco …

Mitigation only
Fix from $1,950 2018-10-05
Ios Xe MEDIUM 6.7
CVE-2018-15371

A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication …

Mitigation only
Fix from $1,600 2018-10-05
Email Security Appliance MEDIUM 5.3
CVE-2018-0447

A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthen…

Mitigation only
Fix from $1,600 2018-10-05
Webex Teams HIGH 8.7
CVE-2018-0436

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization…

Fix: 10.6.0+
Fix from $1,950 2018-10-05
Web Security Appliance MEDIUM 6.7
CVE-2018-0428

A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri…

Mitigation only
Fix from $1,600 2018-08-15
Vbond Orchestrator HIGH 8.8
CVE-2018-0343

A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb…

Fix: 18.3.0+
Fix from $1,950 2018-07-18
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2017-12262

A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow a…

Fix: 1.5+
Fix from $1,950 2017-11-02
Evolved Programmable Network Manager HIGH 8.8
CVE-2016-1406

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticate…

Mitigation only
Fix from $1,950 2016-05-25
Email Security Appliance Firmeware HIGH 7.5
CVE-2016-1315

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow…

Mitigation only
Fix from $1,950 2016-02-12
Prime Security Manager HIGH 8.8
CVE-2016-1301

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9…

Mitigation only
Fix from $1,950 2016-02-07
Nx Os HIGH 8.8
CVE-2016-1302

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switche…

Fix: 2.50+
Fix from $1,950 2016-02-07
Identity Services Engine Software MEDIUM 6.5
CVE-2015-6317

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct re…

Mitigation only
Fix from $1,600 2016-01-23
iOS MEDIUM 5.0
CVE-2015-6366

Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended net…

Mitigation only
Fix from $1,600 2015-11-13
Unified Web And E Mail Interaction Manager MEDIUM 5.5
CVE-2015-4299

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default …

Mitigation only
Fix from $1,600 2015-08-19
Unified Web And E Mail Interaction Manager MEDIUM 6.5
CVE-2015-4298

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to rea…

Mitigation only
Fix from $1,600 2015-08-19
Firesight System Software MEDIUM 6.4
CVE-2015-4302

The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in…

Mitigation only
Fix from $1,600 2015-08-19
Telepresence Tc Software MEDIUM 6.4
CVE-2015-4271

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request pa…

Mitigation only
Fix from $1,600 2015-07-15