Vulnerability index

Browse CVEs

162 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.3 CVE-2016-6474 A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthe… iOS Mitigation only Fix from $1,9502016-12-14 CRITICAL 9.8 CVE-2016-6452 A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authent… Prime Home Mitigation only Fix from $2,3002016-11-03 CRITICAL 9.8 CVE-2016-6397 A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Service… Ip Interoperability And Collaboration System Mitigation only Fix from $2,3002016-10-28 HIGH 7.8 CVE-2016-6434 Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CL… Secure Firewall Management Center No fix yet Fix from $1,9502016-10-06 HIGH 8.1 CVE-2016-6377 Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma… Media Origination System Suite Mitigation only Fix from $1,9502016-09-03 HIGH 8.8 CVE-2015-6397 Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obt… Rv110w Wireless N Vpn Firewall Firmware Mitigation only Fix from $1,9502016-08-08 HIGH 7.5 CVE-2016-1427 The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo… Prime Network Registrar Mitigation only Fix from $1,9502016-06-18 HIGH 7.5 CVE-2016-1402 The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati… Identity Services Engine Software Mitigation only Fix from $1,9502016-05-21 CRITICAL 9.8 CVE-2016-1387 The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8… Telepresence Tc Software Mitigation only Fix from $2,3002016-05-05 CRITICAL 9.8 CVE-2015-6314 Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change conf… Wireless Lan Controller Software Mitigation only Fix from $2,3002016-01-15 HIGH 7.5 CVE-2015-6401EPSS 8% Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci… Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter No fix yet Fix from $1,9502015-12-14 HIGH 9.0 CVE-2015-6389 Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-12-13 HIGH 9.3 CVE-2015-6280 The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before… iOS Mitigation only Fix from $1,9502015-09-28 MEDIUM 5.0 CVE-2015-6266 The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote att… Identity Services Engine Software Mitigation only Fix from $1,6002015-08-28 MEDIUM 6.4 CVE-2015-0670 The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows re… Spa500 Firmware Mitigation only Fix from $1,6002015-03-21 HIGH 10.0 CVE-2015-0653 The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before… Expressway Software Mitigation only Fix from $1,9502015-03-13 MEDIUM 5.0 CVE-2014-8033 The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID… Webex Meetings Server Mitigation only Fix from $1,6002015-01-09 MEDIUM 5.0 CVE-2014-3402 The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection … Intrusion Prevention System after 7.0 Fix from $1,6002014-10-10 MEDIUM 6.9 CVE-2014-3312 The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex… Spa 301 1 Line Ip Phone Mitigation only Fix from $1,6002014-07-09 MEDIUM 6.8 CVE-2014-2181 Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demo… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-05-07 MEDIUM 6.4 CVE-2012-5032 The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows re… iOS after 15.1 Fix from $1,6002014-04-23 MEDIUM 5.0 CVE-2012-4658 The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage… iOS after 15.1 Fix from $1,6002014-04-23 MEDIUM 5.0 CVE-2014-2128 The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 be… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2014-0743 The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote atta… Unified Communications Manager after 10.0 Fix from $1,6002014-02-27 MEDIUM 5.0 CVE-2014-0733 The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce aut… Unified Communications Manager after 10.0 Fix from $1,6002014-02-20 MEDIUM 5.0 CVE-2014-0732 The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enfor… Unified Communications Manager after 10.0 Fix from $1,6002014-02-20 MEDIUM 5.0 CVE-2014-0722 The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers … Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 5.0 CVE-2014-0725 Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i… Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 6.8 CVE-2014-0674 Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o… Video Surveillance Operations Manager Mitigation only Fix from $1,6002014-01-24 MEDIUM 5.4 CVE-2013-6979 The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, w… Ios Xe Mitigation only Fix from $1,6002013-12-23