Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pix HIGH 7.1
CVE-2007-2464

Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allo…

Fix: after 7.2.2
Fix from $1,950 2007-05-02
Netflow Collection Engine HIGH 10.0
CVE-2007-2282

Cisco Network Services (CNS) NetFlow Collection Engine (NFC) before 6.0 has an nfcuser account with the default password nfcuser, which allows remote…

Mitigation only
Fix from $1,950 2007-04-26
Wireless Lan Controller Software HIGH 10.0
CVE-2007-2036

The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-…

Patch available
Fix from $1,950 2007-04-16
Wireless Control System HIGH 9.0
CVE-2007-2034

Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the Supe…

Fix: after 4.0.95
Fix from $1,950 2007-04-16
Wireless Control System HIGH 7.8
CVE-2007-2035

Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows re…

Fix: after 4.0.95
Fix from $1,950 2007-04-16
Wireless Control System HIGH 7.5
CVE-2007-2032

Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers t…

Patch available
Fix from $1,950 2007-04-16
Wireless Control System MEDIUM 6.5
CVE-2007-2033

Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by …

Fix: after 4.0.95
Fix from $1,600 2007-04-16
Wireless Lan Controller Software MEDIUM 6.2
CVE-2007-2040

Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which a…

Fix: 3.2.185.0 / 4.0.206.0+
Fix from $1,600 2007-04-16
2000 Wireless Lan Controller MEDIUM 6.1
CVE-2007-2038

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attack…

Mitigation only
Fix from $1,600 2007-04-16
Wireless Lan Controller Software MEDIUM 6.1
CVE-2007-2039

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attack…

Fix: 3.2.171.5 / 4.0.206.0+
Fix from $1,600 2007-04-16
Unified Callmanager HIGH 7.8
CVE-2007-1834

Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a d…

Patch available
Fix from $1,950 2007-04-03
Unified Callmanager MEDIUM 5.0
CVE-2007-1833

The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.…

Patch available
Fix from $1,600 2007-04-03
Unified Callmanager HIGH 7.8
CVE-2007-1826

Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (…

Patch available
Fix from $1,950 2007-04-02
Trust Agent HIGH 7.5
CVE-2007-1800

Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to ga…

Mitigation only
Fix from $1,950 2007-04-02
7940 Router MEDIUM 5.0
CVE-2007-1542EPSS 9%

Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service v…

Mitigation only
Fix from $1,600 2007-03-20
Network Analysis Module HIGH 10.0
CVE-2007-1257EPSS 7%

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNM…

Mitigation only
Fix from $1,950 2007-03-03
Catalyst 6000 MEDIUM 6.1
CVE-2007-1258

Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 650…

Mitigation only
Fix from $1,600 2007-03-03
Unified Ip Phone Firmware 7906g HIGH 7.2
CVE-2007-1072

The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows l…

Patch available
Fix from $1,950 2007-02-22
Unified Ip Conference Station 7935 Firmware HIGH 10.0
CVE-2007-1062

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP se…

Fix: after 3.3
Fix from $1,950 2007-02-22
Unified Ip Phone Firmware 7906g HIGH 10.0
CVE-2007-1063

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded usernam…

Patch available
Fix from $1,950 2007-02-22
Secure Services Client HIGH 7.2
CVE-2007-1067

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been depl…

Mitigation only
Fix from $1,950 2007-02-22
Secure Services Client HIGH 7.2
CVE-2007-1068

The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authe…

Patch available
Fix from $1,950 2007-02-22
Secure Services Client MEDIUM 6.8
CVE-2007-1064

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been depl…

Patch available
Fix from $1,600 2007-02-22
Secure Services Client MEDIUM 6.8
CVE-2007-1065

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been depl…

Patch available
Fix from $1,600 2007-02-22
Secure Services Client MEDIUM 6.8
CVE-2007-1066

Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been depl…

Patch available
Fix from $1,600 2007-02-22
Asa 5500 HIGH 9.0
CVE-2007-0960

Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, all…

Patch available
Fix from $1,950 2007-02-16
Firewall Services Module HIGH 9.0
CVE-2007-0968

Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in…

Patch available
Fix from $1,950 2007-02-16
Asa 5500 HIGH 7.8
CVE-2007-0959

Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause…

Patch available
Fix from $1,950 2007-02-16
Asa 5500 HIGH 7.8
CVE-2007-0961

Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.…

Patch available
Fix from $1,950 2007-02-16
Firewall Services Module HIGH 7.8
CVE-2007-0962

Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before …

Patch available
Fix from $1,950 2007-02-16