Vulnerability index

Browse CVEs

36 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Industrial Network Director MEDIUM 5.9
CVE-2019-1940

A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote…

Fix: 1.7+
Fix from $1,600 2019-07-17
Nexus 9332pq Firmware CRITICAL 9.8
CVE-2019-1804

A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow a…

Mitigation only
Fix from $2,300 2019-05-03
Wap121 Firmware MEDIUM 5.3
CVE-2018-0412

A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireles…

Fix: after 1.0.6.6
Fix from $1,600 2018-08-15
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0281

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
Secure Firewall Management Center MEDIUM 5.8
CVE-2018-0283

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to restart an instance of …

Mitigation only
Fix from $1,600 2018-05-02
iOS MEDIUM 5.9
CVE-2011-4667

The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS…

Mitigation only
Fix from $1,600 2017-09-25
Firesight System Software HIGH 7.5
CVE-2017-6766

A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.…

Mitigation only
Fix from $1,950 2017-08-07
Content Security Management Appliance MEDIUM 5.9
CVE-2016-1411

A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), a…

Mitigation only
Fix from $1,600 2016-12-14
Ios Xe MEDIUM 5.0
CVE-2014-3403

The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spo…

Mitigation only
Fix from $1,600 2014-10-10
Cisco Technical Support MEDIUM 5.4
CVE-2014-5868

The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which all…

Mitigation only
Fix from $1,600 2014-09-11
Webex Meetings Server MEDIUM 5.8
CVE-2014-3302

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allow…

Fix: after 1.5
Fix from $1,600 2014-08-01
Unified Communications Manager MEDIUM 6.2
CVE-2014-0741

The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager HIGH 7.3
CVE-2013-7030EPSS 5%

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phon…

No fix yet
Fix from $1,950 2013-12-12
Unified Computing System MEDIUM 5.8
CVE-2012-4115

The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2013-10-21
Unified Computing System MEDIUM 5.8
CVE-2012-4114

The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man-in-the-middle attackers to w…

Mitigation only
Fix from $1,600 2013-10-19
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5507

The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote …

Mitigation only
Fix from $1,950 2013-10-13
Unified Computing System MEDIUM 5.8
CVE-2012-4073

The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-…

Mitigation only
Fix from $1,600 2013-09-20
Socialminer MEDIUM 5.0
CVE-2013-5492

administration.jsp in Cisco SocialMiner allows remote attackers to obtain sensitive information by sniffing the network for HTTP client-server traffi…

Mitigation only
Fix from $1,600 2013-09-13
Nx Os MEDIUM 5.8
CVE-2013-1212

The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoo…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.8
CVE-2013-1208

The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (V…

Mitigation only
Fix from $1,600 2013-05-29
Network Admission Control MEDIUM 5.8
CVE-2013-1124

The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during …

Mitigation only
Fix from $1,600 2013-02-28
Anyconnect Secure Mobility Client MEDIUM 5.8
CVE-2012-2499

The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate…

Mitigation only
Fix from $1,600 2012-08-06
iOS HIGH 7.8
CVE-2012-0386

The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows …

Mitigation only
Fix from $1,950 2012-03-29
iOS HIGH 7.5
CVE-2012-0381

The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S,…

Fix: 3.2.2sg / 3.4.1s+
Fix from $1,950 2012-03-29
iOS HIGH 10.0
CVE-2011-0935

The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass a…

Mitigation only
Fix from $1,950 2011-04-14
Unified Videoconferencing System 5110 Firmware MEDIUM 6.4
CVE-2010-4304

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (…

Mitigation only
Fix from $1,600 2010-11-22
Unified Videoconferencing System 5110 Firmware MEDIUM 5.0
CVE-2010-4305

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified…

Mitigation only
Fix from $1,600 2010-11-22
Unified Wireless Network Solution Software HIGH 10.0
CVE-2010-2978

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, wh…

Mitigation only
Fix from $1,950 2010-08-10
Ironport Desktop Flag Plugin For Outlook MEDIUM 5.0
CVE-2010-1568

The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously compose…

Fix: after 6.5.0
Fix from $1,600 2010-05-14
iOS HIGH 7.8
CVE-2010-0578

The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service …

Patch available
Fix from $1,950 2010-03-25