Vulnerability index

Browse CVEs

162 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Prime Collaboration CRITICAL 9.8
CVE-2018-0318

A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gai…

Fix: after 12.1
Fix from $2,300 2018-06-07
Prime Collaboration CRITICAL 9.8
CVE-2018-0319

A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to …

Fix: after 12.1
Fix from $2,300 2018-06-07
Prime Collaboration CRITICAL 9.8
CVE-2018-0321

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the Java Remote Method Invo…

Fix: after 11.6
Fix from $2,300 2018-06-07
Digital Network Architecture Center CRITICAL 9.8
CVE-2018-0271

A vulnerability in the API gateway of the Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass a…

Fix: 1.1.2+
Fix from $2,300 2018-05-17
Unified Computing System Director CRITICAL 9.9
CVE-2018-0238EPSS 5%

A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, …

Mitigation only
Fix from $2,300 2018-04-19
Ios Xe HIGH 8.8
CVE-2018-0195

A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the AP…

Fix: 16.2.2+
Fix from $1,950 2018-03-28
iOS MEDIUM 6.5
CVE-2018-0163

A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to…

Mitigation only
Fix from $1,600 2018-03-28
Asyncos MEDIUM 5.6
CVE-2018-0087

A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP serv…

Mitigation only
Fix from $1,600 2018-03-08
Elastic Services Controller CRITICAL 9.8
CVE-2018-0121

A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unau…

Mitigation only
Fix from $2,300 2018-02-22
Mobility Services Engine HIGH 7.2
CVE-2018-0116

A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subsc…

Mitigation only
Fix from $1,950 2018-02-08
Emergency Responder CRITICAL 9.8
CVE-2017-12337EPSS 6%

A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an u…

Mitigation only
Fix from $2,300 2017-11-16
Identity Services Engine Software HIGH 7.5
CVE-2017-12316

A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul…

Mitigation only
Fix from $1,950 2017-11-16
Aironet 1800 Firmware HIGH 7.5
CVE-2017-12281

A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Air…

Mitigation only
Fix from $1,950 2017-11-02
Cloud Services Platform 2100 CRITICAL 9.9
CVE-2017-12251

A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciou…

Mitigation only
Fix from $2,300 2017-10-19
Ios Xe CRITICAL 9.8
CVE-2017-12229EPSS 5%

A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $2,300 2017-09-29
Ios Xe CRITICAL 9.8
CVE-2017-12236

A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, r…

Mitigation only
Fix from $2,300 2017-09-29
Prime Lan Management Solution MEDIUM 6.5
CVE-2017-12225

A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another u…

Mitigation only
Fix from $1,600 2017-09-07
Policy Suite MEDIUM 5.3
CVE-2017-6781

A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local…

Mitigation only
Fix from $1,600 2017-08-17
Identity Services Engine CRITICAL 9.8
CVE-2017-6747EPSS 5%

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local …

Mitigation only
Fix from $2,300 2017-08-07
Ultra Services Framework CRITICAL 9.1
CVE-2017-6711

A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain u…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Unified Contact Center Express MEDIUM 6.1
CVE-2017-6722

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauth…

Mitigation only
Fix from $1,600 2017-07-04
Prime Collaboration Provisioning MEDIUM 5.9
CVE-2017-6703

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack a…

Mitigation only
Fix from $1,600 2017-07-04
iOS MEDIUM 5.3
CVE-2017-6624

A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthoriz…

Mitigation only
Fix from $1,600 2017-05-03
Integrated Management Controller Supervisor MEDIUM 5.4
CVE-2017-6617

A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) c…

Mitigation only
Fix from $1,600 2017-04-20
Webex Meetings Server MEDIUM 6.5
CVE-2017-3880

An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting infor…

Mitigation only
Fix from $1,600 2017-03-17
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2017-3867

A vulnerability in the Border Gateway Protocol (BGP) Bidirectional Forwarding Detection (BFD) implementation of Cisco Adaptive Security Appliance (AS…

Mitigation only
Fix from $1,600 2017-03-17
Aironet Access Point Software CRITICAL 9.8
CVE-2017-3831EPSS 5%

A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass au…

Mitigation only
Fix from $2,300 2017-03-15
Wireless Lan Controller Firmware HIGH 8.8
CVE-2017-3854

A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC…

Mitigation only
Fix from $1,950 2017-03-15
Cisco Prime Home CRITICAL 10.0
CVE-2017-3791

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions…

Mitigation only
Fix from $2,300 2017-02-01
Webex Meetings Server MEDIUM 5.4
CVE-2017-3795

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-ad…

Mitigation only
Fix from $1,600 2017-01-26