← Back

Cisco

cisco

6,669 CVEs • 6,229 products

Products (6,229)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber
Roomos
roomos

CVEs (6,669)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Cisco
Sun
3Evolved Programmable Network Manager
OpensolarisPrime Infrastructure
May 6, 2026
Apr 6, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an H...Show more
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.Show less
1Cisco
2Asa With Firepower Services
Firesight System Software
May 6, 2026
Apr 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.
1Cisco
2Ios
Nx Os
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug...Show more
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.Show less
6Cisco
LenovoSamsung+3 more
6Gs1900 10hp Firmware
Ios XeKeymouse Firmware+3 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
7Cisco
IntelNetgear+4 more
7Core I5 9400f Firmware
Gs1900 10hp FirmwareIos Xe+4 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Insta...Show more
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.Show less
6Cisco
NetgearSamsung+3 more
6Gs1900 10hp Firmware
Ios XeJr6150 Firmware+3 more
May 6, 2026
Mar 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.
7Cisco
LenovoNetgear+4 more
7Gs1900 10hp Firmware
Ios XeJr6150 Firmware+4 more
May 6, 2026
Mar 26, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
1Cisco
1Ios Xr
May 6, 2026
Mar 24, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwri...Show more
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.Show less
1Cisco
1Ios
May 6, 2026
Mar 24, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.
1Cisco
1Ios Xr
May 6, 2026
Mar 12, 2016
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header in a UDP packet, which allows remote attackers to cause a denial of se...Show more
Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header in a UDP packet, which allows remote attackers to cause a denial of service (line-card restart) via a crafted packet, aka Bug ID CSCuw56900.Show less
1Cisco
1Prime Lan Management Solution
May 6, 2026
Mar 12, 2016
N/A· v4
7.1 HIGH· v3
3.0 LOW· v2
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivit...Show more
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390.Show less
1Cisco
1Telepresence Video Communication Server Software
May 6, 2026
Mar 12, 2016
N/A· v4
6.5 MEDIUM· v3
8.0 HIGH· v2
Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026.
1Cisco
2Dpc2203 Cable Modem Firmware
Epc2203 Cable Modem Firmware
May 6, 2026
Mar 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935.
1Cisco
1Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter
May 6, 2026
Mar 9, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The administration interface on Cisco DPQ3925 devices with firmware r1 allows remote attackers to cause a denial of service (device restart) via a crafted HTTP request, aka Bug ID CSCup48105.
1Cisco
1Dpc3939 Wireless Residential Voice Gateway Firmware
May 6, 2026
Mar 9, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCus49506.
1Cisco
1Asa 5500 Csc Ssm Firmware
May 6, 2026
Mar 9, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption...Show more
The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of HTTPS packets, aka Bug ID CSCue76147.Show less
1Cisco
1Prime Infrastructure
May 6, 2026
Mar 3, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494.
1Cisco
1Prime Infrastructure
May 6, 2026
Mar 3, 2016
N/A· v4
6.4 MEDIUM· v3
5.5 MEDIUM· v2
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with a...Show more
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.Show less
1Cisco
1Cisco Policy Suite
May 6, 2026
Mar 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified da...Show more
The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut85211.Show less
1Cisco
1Firesight System Software
May 6, 2026
Mar 3, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID...Show more
Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.Show less