Vulnerability index

Browse CVEs

162 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
iOS HIGH 7.3
CVE-2016-6474

A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthe…

Mitigation only
Fix from $1,950 2016-12-14
Prime Home CRITICAL 9.8
CVE-2016-6452

A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authent…

Mitigation only
Fix from $2,300 2016-11-03
Ip Interoperability And Collaboration System CRITICAL 9.8
CVE-2016-6397

A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Service…

Mitigation only
Fix from $2,300 2016-10-28
Secure Firewall Management Center HIGH 7.8
CVE-2016-6434

Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CL…

No fix yet
Fix from $1,950 2016-10-06
Media Origination System Suite HIGH 8.1
CVE-2016-6377

Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…

Mitigation only
Fix from $1,950 2016-09-03
Rv110w Wireless N Vpn Firewall Firmware HIGH 8.8
CVE-2015-6397

Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt…

Mitigation only
Fix from $1,950 2016-08-08
Prime Network Registrar HIGH 7.5
CVE-2016-1427

The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…

Mitigation only
Fix from $1,950 2016-06-18
Identity Services Engine Software HIGH 7.5
CVE-2016-1402

The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…

Mitigation only
Fix from $1,950 2016-05-21
Telepresence Tc Software CRITICAL 9.8
CVE-2016-1387

The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8…

Mitigation only
Fix from $2,300 2016-05-05
Wireless Lan Controller Software CRITICAL 9.8
CVE-2015-6314

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf…

Mitigation only
Fix from $2,300 2016-01-15
Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter HIGH 7.5
CVE-2015-6401EPSS 8%

Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci…

No fix yet
Fix from $1,950 2015-12-14
Prime Collaboration Assurance HIGH 9.0
CVE-2015-6389

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH…

Mitigation only
Fix from $1,950 2015-12-13
iOS HIGH 9.3
CVE-2015-6280

The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before…

Mitigation only
Fix from $1,950 2015-09-28
Identity Services Engine Software MEDIUM 5.0
CVE-2015-6266

The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote att…

Mitigation only
Fix from $1,600 2015-08-28
Spa500 Firmware MEDIUM 6.4
CVE-2015-0670

The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows re…

Mitigation only
Fix from $1,600 2015-03-21
Expressway Software HIGH 10.0
CVE-2015-0653

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before…

Mitigation only
Fix from $1,950 2015-03-13
Webex Meetings Server MEDIUM 5.0
CVE-2014-8033

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID…

Mitigation only
Fix from $1,600 2015-01-09
Intrusion Prevention System MEDIUM 5.0
CVE-2014-3402

The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection …

Fix: after 7.0
Fix from $1,600 2014-10-10
Spa 301 1 Line Ip Phone MEDIUM 6.9
CVE-2014-3312

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex…

Mitigation only
Fix from $1,600 2014-07-09
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-2181

Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demo…

Mitigation only
Fix from $1,600 2014-05-07
iOS MEDIUM 6.4
CVE-2012-5032

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows re…

Fix: after 15.1
Fix from $1,600 2014-04-23
iOS MEDIUM 5.0
CVE-2012-4658

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage…

Fix: after 15.1
Fix from $1,600 2014-04-23
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-2128

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 be…

Mitigation only
Fix from $1,600 2014-04-10
Unified Communications Manager MEDIUM 5.0
CVE-2014-0743

The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote atta…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 5.0
CVE-2014-0733

The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce aut…

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager MEDIUM 5.0
CVE-2014-0732

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enfor…

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager MEDIUM 5.0
CVE-2014-0722

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0725

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-02-13
Video Surveillance Operations Manager MEDIUM 6.8
CVE-2014-0674

Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2014-01-24
Ios Xe MEDIUM 5.4
CVE-2013-6979

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, w…

Mitigation only
Fix from $1,600 2013-12-23