← Back

Cisco

cisco

6,669 CVEs • 6,229 products

Products (6,229)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber
Roomos
roomos

CVEs (6,669)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
emWEB on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (daemon crash) via a request for a document whose name contains space...Show more
emWEB on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote attackers to cause a denial of service (daemon crash) via a request for a document whose name contains space characters, aka Bug ID CSCsy08416.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote authenticated users to cause a denial of service (device crash) via a high volume of IPs...Show more
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allows remote authenticated users to cause a denial of service (device crash) via a high volume of IPsec traffic, aka Bug ID CSCsx52748.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
9.0 HIGH· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users...Show more
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET connections should be permitted, which allows remote authenticated users to bypass intended access restrictions via vectors involving the "lowest security level interface," aka Bug ID CSCsv40504.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allows remote attackers to cause a denial of service (block exhaustion) via multicast traffic, ak...Show more
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allows remote attackers to cause a denial of service (block exhaustion) via multicast traffic, aka Bug ID CSCtg63992.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(4) and earlier allow remote attackers to cause a denial of service via a flood of packets, aka Bug ID CSCtg06316.
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier allow remote attackers to cause a denial of service (block exhaustion) via EIGRP traffic that triggers an EIGRP multicast stor...Show more
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier allow remote attackers to cause a denial of service (block exhaustion) via EIGRP traffic that triggers an EIGRP multicast storm, aka Bug ID CSCtf20269.Show less
1Cisco
1Ios
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertise...Show more
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package, aka Bug ID CSCti33534.Show less
1Cisco
45500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500+1 more
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
7.8 HIGH· v2
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PIX Security Appliances devices, allows re...Show more
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PIX Security Appliances devices, allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package, aka Bug ID CSCti24526.Show less
1Cisco
35500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareAsa 5500
Apr 29, 2026
Jan 7, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remote attackers to cause a denial of service (ASDM syslog outage) via a long URL, aka Bug IDs CSCsm11264 and CSCtb92911.
1Cisco
9Asa 5500
Pix 500Vpn 3000 Concentrator+6 more
Apr 29, 2026
Nov 30, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive...Show more
The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series devices, and VPN Concentrators 3000 series devices responds to an Aggressive Mode IKE Phase I message only when the group name is configured on the device, which allows remote attackers to enumerate valid group names via a series of IKE negotiation attempts, aka Bug ID CSCtj96108, a different vulnerability than CVE-2005-2025.Show less
1Cisco
14Unified Videoconferencing System 3515 Multipoint Control Unit
Unified Videoconferencing System 3515 Multipoint Control Unit FirmwareUnified Videoconferencing System 3522 Basic Rate Interface Gateway+11 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unifie...Show more
Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface credentials, which allows remote attackers to obtain sensitive information by reading a (1) cleartext or (2) base64-encoded cleartext cookie, aka Bug ID CSCti54052.Show less
1Cisco
14Unified Videoconferencing System 3515 Multipoint Control Unit
Unified Videoconferencing System 3515 Multipoint Control Unit FirmwareUnified Videoconferencing System 3522 Basic Rate Interface Gateway+11 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI...Show more
The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack, aka Bug ID CSCti54048.Show less
1Cisco
4Unified Videoconferencing System 5110
Unified Videoconferencing System 5110 FirmwareUnified Videoconferencing System 5115+1 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by r...Show more
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by reading this file, aka Bug ID CSCti54043.Show less
1Cisco
4Unified Videoconferencing System 5110
Unified Videoconferencing System 5110 FirmwareUnified Videoconferencing System 5115+1 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) o...Show more
/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010.Show less
1Cisco
4Unified Videoconferencing System 5110
Unified Videoconferencing System 5110 FirmwareUnified Videoconferencing System 5115+1 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier for remote attackers t...Show more
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, which makes it easier for remote attackers to obtain access via the (a) FTP or (b) SSH daemon, aka Bug ID CSCti54008.Show less
1Cisco
14Unified Videoconferencing System 3515 Multipoint Control Unit
Unified Videoconferencing System 3515 Multipoint Control Unit FirmwareUnified Videoconferencing System 3522 Basic Rate Interface Gateway+11 more
Apr 29, 2026
Nov 22, 2010
N/A· v4
N/A· v3
8.5 HIGH· v2
goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Ga...Show more
goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), allows remote authenticated administrators to execute arbitrary commands via the username field, related to a "shell command injection vulnerability," aka Bug ID CSCti54059.Show less
1Cisco
1Intelligent Contact Manager
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (...Show more
Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.Show less
1Cisco
1Unified Communications Manager
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters...Show more
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.Show less
1Cisco
7Ciscoworks Common Services
Ciscoworks Lan Management SolutionQos Policy Manager+4 more
Apr 29, 2026
Oct 29, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or...Show more
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.Show less
1Cisco
1Secure Desktop
Apr 29, 2026
Oct 14, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable fi...Show more
Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.Show less