Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Sd Wan CRITICAL 9.9
CVE-2020-3374

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass author…

Fix: 18.4.5 / 19.2.2+
Fix from $2,300 2020-07-31
Prime License Manager CRITICAL 9.8
CVE-2020-3140

A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain…

Fix: after 11.5
Fix from $2,300 2020-07-16
Rv110w Firmware MEDIUM 5.9
CVE-2020-3150

A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote…

Fix: 1.2.2.8 / 1.3.1.7+
Fix from $1,600 2020-07-16
Unified Ip Phone 6901 Firmware MEDIUM 5.3
CVE-2020-3360

A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sens…

Fix: after 12.8
Fix from $1,600 2020-06-18
Ios Xr MEDIUM 5.3
CVE-2020-3364

A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could all…

Mitigation only
Fix from $1,600 2020-06-18
Application Policy Infrastructure Controller MEDIUM 5.5
CVE-2020-3335

A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive informa…

Fix: 1.1.2.20+
Fix from $1,600 2020-06-03
Ios Xe CRITICAL 9.8
CVE-2020-3227

A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenti…

Mitigation only
Fix from $2,300 2020-06-03
Ios Xe HIGH 8.8
CVE-2020-3229EPSS 5%

A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remo…

Patch available
Fix from $1,950 2020-06-03
Ios Xe HIGH 7.8
CVE-2019-12671

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execu…

Mitigation only
Fix from $1,950 2019-09-25
iOS HIGH 8.8
CVE-2019-12648

A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access t…

Mitigation only
Fix from $1,950 2019-09-25
Sf 220 24 Firmware CRITICAL 9.1
CVE-2019-1912EPSS 17%

A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to …

Fix: 1.1.4.4+
Fix from $2,300 2019-08-07
Sd Wan Firmware HIGH 8.8
CVE-2019-1626

A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated priv…

Fix: after 18.3.6
Fix from $1,950 2019-06-20
Nx Os HIGH 7.8
CVE-2019-1603

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrat…

Fix: 7.0+
Fix from $1,950 2019-03-08
Nx Os HIGH 7.8
CVE-2019-1604

A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privil…

Fix: 6.2 / 7.0+
Fix from $1,950 2019-03-08
Adaptive Security Appliance Software HIGH 8.1
CVE-2018-15465

A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (le…

Fix: 9.4.4.29 / 9.6.4.20+
Fix from $1,950 2018-12-24
Ucs Director MEDIUM 6.5
CVE-2018-15405

A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director coul…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0460

A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any fil…

Mitigation only
Fix from $1,600 2018-10-05
Network Functions Virtualization Infrastructure MEDIUM 6.5
CVE-2018-0459

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote at…

Mitigation only
Fix from $1,600 2018-10-05
Nx Os HIGH 7.8
CVE-2018-0337

A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrar…

Mitigation only
Fix from $1,950 2018-06-21
Unified Computing System HIGH 7.8
CVE-2018-0338

A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local att…

Mitigation only
Fix from $1,950 2018-06-07
Secure Firewall Management Center MEDIUM 6.5
CVE-2018-0278

A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data…

Mitigation only
Fix from $1,600 2018-05-02
Webex Meetings Server HIGH 8.1
CVE-2018-0110

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has b…

Mitigation only
Fix from $1,950 2018-01-18
Prime Infrastructure MEDIUM 5.9
CVE-2018-0096

A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Mitigation only
Fix from $1,600 2018-01-18
Identity Services Engine HIGH 7.8
CVE-2017-12261

A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local at…

Mitigation only
Fix from $1,950 2017-11-02
Asr 5000 Series Software HIGH 7.5
CVE-2017-6672

A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x co…

Mitigation only
Fix from $1,950 2017-07-25
Unified Computing System Director HIGH 8.8
CVE-2017-3801

A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary work…

Mitigation only
Fix from $1,950 2017-02-15
Carrier Routing System MEDIUM 5.8
CVE-2012-1342

Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

Mitigation only
Fix from $1,600 2012-08-06
iOS HIGH 9.3
CVE-2007-2586EPSS 14%

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, an…

No fix yet
Fix from $1,950 2007-05-10