Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Prime Lan Management Solution HIGH 7.1
CVE-2016-1360

Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows…

Mitigation only
Fix from $1,950 2016-03-12
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2016-1338

Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) vi…

Mitigation only
Fix from $1,600 2016-03-12
Dpc2203 Cable Modem Firmware CRITICAL 9.8
CVE-2016-1327EPSS 7%

Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2016-03-09
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter HIGH 7.5
CVE-2016-1326

The administration interface on Cisco DPQ3925 devices with firmware r1 allows remote attackers to cause a denial of service (device restart) via a cr…

Mitigation only
Fix from $1,950 2016-03-09
Dpc3939 Wireless Residential Voice Gateway Firmware HIGH 7.5
CVE-2016-1325

The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request…

Mitigation only
Fix from $1,950 2016-03-09
Asa 5500 Csc Ssm Firmware HIGH 7.5
CVE-2016-1312

The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices a…

Mitigation only
Fix from $1,950 2016-03-09
Prime Infrastructure HIGH 8.8
CVE-2016-1359

Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewi…

Mitigation only
Fix from $1,950 2016-03-03
Prime Infrastructure MEDIUM 6.4
CVE-2016-1358

Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML d…

Mitigation only
Fix from $1,600 2016-03-03
Cisco Policy Suite MEDIUM 5.3
CVE-2016-1357

The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote…

Mitigation only
Fix from $1,600 2016-03-03
Web Security Appliance MEDIUM 5.3
CVE-2016-1288

The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to…

Mitigation only
Fix from $1,600 2016-03-03
Unified Computing System HIGH 7.5
CVE-2015-0718

Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attack…

Fix: 2.50 / 2017-01-06+
Fix from $1,950 2016-03-03
Firesight System Software MEDIUM 6.1
CVE-2016-1355

Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remo…

Mitigation only
Fix from $1,600 2016-03-03
Unified Communications Domain Manager MEDIUM 6.1
CVE-2016-1354

Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arb…

Mitigation only
Fix from $1,600 2016-03-03
Videoscape Distribution Suite For Internet Streaming MEDIUM 5.3
CVE-2016-1353

The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly in…

Mitigation only
Fix from $1,600 2016-03-01
Secure Firewall Management Center MEDIUM 5.3
CVE-2016-1342

The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2016-02-26
Application Control Engine Software HIGH 8.8
CVE-2016-1297

The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC res…

Mitigation only
Fix from $1,950 2016-02-26
Nx Os CRITICAL 9.8
CVE-2016-1341

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…

Mitigation only
Fix from $2,300 2016-02-24
Asr 5000 Series Software HIGH 7.5
CVE-2016-1335

The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key auth…

Mitigation only
Fix from $1,950 2016-02-19
Small Business Wireless Access Points Firmware MEDIUM 5.3
CVE-2016-1334

Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request…

Mitigation only
Fix from $1,600 2016-02-17
iOS MEDIUM 6.5
CVE-2016-1333

Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload)…

Mitigation only
Fix from $1,600 2016-02-17
Universal Small Cell Firmware MEDIUM 5.8
CVE-2016-1321

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to…

Mitigation only
Fix from $1,600 2016-02-15
Spark MEDIUM 5.3
CVE-2016-1324

The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page,…

Mitigation only
Fix from $1,600 2016-02-12
Spark HIGH 7.5
CVE-2016-1322

The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via un…

Mitigation only
Fix from $1,950 2016-02-12
Prime Collaboration MEDIUM 6.7
CVE-2016-1320

The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges,…

Mitigation only
Fix from $1,600 2016-02-12
Email Security Appliance Firmeware HIGH 7.5
CVE-2016-1315

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allow…

Mitigation only
Fix from $1,950 2016-02-12
Adaptive Security Appliance Software CRITICAL 9.8
CVE-2016-1287EPSS 77%

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before…

No fix yet
Fix from $2,300 2016-02-11
Application Policy Infrastructure Controller Enterprise Module MEDIUM 6.1
CVE-2016-1318

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-09
Telepresence Video Communication Server Software MEDIUM 5.3
CVE-2016-1316

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se…

Mitigation only
Fix from $1,600 2016-02-09
Webex Meetings Server MEDIUM 6.1
CVE-2016-1309

Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meetings Server 2.5.1.5 allow remote attackers to inject arbitrary web script or H…

Mitigation only
Fix from $1,600 2016-02-07
Application Policy Infrastructure Controller Enterprise Module MEDIUM 6.1
CVE-2016-1305

Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-07