Vulnerability index

Browse CVEs

129 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.3 CVE-2019-1759 A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unaut… Ios Xe Patch available Fix from $1,6002019-03-28 HIGH 7.5 CVE-2019-1763 A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an una… Ip Phone 8821 Firmware 11.0 / 12.5+ Fix from $1,9502019-03-22 MEDIUM 6.5 CVE-2019-1690 A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adj… Application Policy Infrastructure Controller 4.2+ Fix from $1,6002019-03-11 HIGH 7.8 CVE-2019-1601 A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a… Nx Os 6.0 / 6.2+ Fix from $1,9502019-03-08 HIGH 7.8 CVE-2019-1664 A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in … Hyperflex Hx Data Platform Mitigation only Fix from $1,9502019-02-21 MEDIUM 5.3 CVE-2019-1666 A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphit… Hyperflex Hx Data Platform Mitigation only Fix from $1,6002019-02-21 MEDIUM 5.3 CVE-2019-1660 A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, rem… Telepresence Management Suite Mitigation only Fix from $1,6002019-02-07 HIGH 7.5 CVE-2019-1653 KEVEPSS 100% A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthentic… Rv320 Firmware Mitigation only Fix from $1,9502019-01-24 HIGH 8.0 CVE-2019-1647 A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized ac… Sd Wan 18.4.0+ Fix from $1,9502019-01-24 HIGH 7.2 CVE-2018-15459 A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain add… Identity Services Engine Mitigation only Fix from $1,9502019-01-23 MEDIUM 6.5 CVE-2018-0484 A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a vi… iOS Mitigation only Fix from $1,6002019-01-10 CRITICAL 9.8 CVE-2018-15394 A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypa… Stealthwatch Enterprise after 6.10.2 Fix from $2,3002018-11-08 MEDIUM 5.4 CVE-2018-15395 A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authentica… Wireless Lan Controller Software Mitigation only Fix from $1,6002018-10-17 HIGH 8.1 CVE-2018-15372 A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco … Ios Xe Mitigation only Fix from $1,9502018-10-05 MEDIUM 6.7 CVE-2018-15371 A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication … Ios Xe Mitigation only Fix from $1,6002018-10-05 MEDIUM 5.3 CVE-2018-0447 A vulnerability in the anti-spam protection mechanisms of Cisco AsyncOS Software for the Cisco Email Security Appliance (ESA) could allow an unauthen… Email Security Appliance Mitigation only Fix from $1,6002018-10-05 HIGH 8.7 CVE-2018-0436 A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization… Webex Teams 10.6.0+ Fix from $1,9502018-10-05 MEDIUM 6.7 CVE-2018-0428 A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate pri… Web Security Appliance Mitigation only Fix from $1,6002018-08-15 HIGH 8.8 CVE-2018-0343 A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arb… Vbond Orchestrator 18.3.0+ Fix from $1,9502018-07-18 HIGH 8.8 CVE-2017-12262 A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow a… Application Policy Infrastructure Controller Enterprise Module 1.5+ Fix from $1,9502017-11-02 HIGH 8.8 CVE-2016-1406 The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticate… Evolved Programmable Network Manager Mitigation only Fix from $1,9502016-05-25 HIGH 7.5 CVE-2016-1315 The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow… Email Security Appliance Firmeware Mitigation only Fix from $1,9502016-02-12 HIGH 8.8 CVE-2016-1301 The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9… Prime Security Manager Mitigation only Fix from $1,9502016-02-07 HIGH 8.8 CVE-2016-1302 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switche… Nx Os 2.50+ Fix from $1,9502016-02-07 MEDIUM 6.5 CVE-2015-6317 Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct re… Identity Services Engine Software Mitigation only Fix from $1,6002016-01-23 MEDIUM 5.0 CVE-2015-6366 Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended net… iOS Mitigation only Fix from $1,6002015-11-13 MEDIUM 5.5 CVE-2015-4299 Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default … Unified Web And E Mail Interaction Manager Mitigation only Fix from $1,6002015-08-19 MEDIUM 6.5 CVE-2015-4298 Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to rea… Unified Web And E Mail Interaction Manager Mitigation only Fix from $1,6002015-08-19 MEDIUM 6.4 CVE-2015-4302 The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in… Firesight System Software Mitigation only Fix from $1,6002015-08-19 MEDIUM 6.4 CVE-2015-4271 Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request pa… Telepresence Tc Software Mitigation only Fix from $1,6002015-07-15