← Back

Cisco

cisco

6,587 CVEs • 6,222 products

Products (6,222)

Click to collapse
Toggle
Ios
ios
Ios Xe
ios_xe
Nx Os
nx_os
Ios Xr
ios_xr
Asyncos
asyncos
Asa 5500
asa_5500
Jabber
jabber

CVEs (6,587)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Pix Firewall Manager
Apr 16, 2026
Oct 10, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.
1Cisco
2Catos
Ios
Apr 16, 2026
Oct 9, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.
1Cisco
1Ios
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.
2Cisco
Dell
2Bsafe Ssl J
Icdn
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by lo...Show more
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.Show less
1Cisco
1Cbos
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.
1Cisco
1Cbos
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to be...Show more
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.Show less
1Cisco
1Ios
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.
1Cisco
1Content Services Switch 11000
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL...Show more
The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.Show less
1Cisco
1Content Services Switch 11000
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
1Cisco
1Catalyst 2900
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.
1Cisco
1Ios
Apr 16, 2026
Jul 24, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.
1Cisco
1Ios
Apr 16, 2026
Jul 21, 2001
N/A· v4
N/A· v3
9.3 HIGH· v2
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
1Cisco
1Ios
Apr 16, 2026
Jul 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.
1Cisco
1Sn 5420 Storage Router Firmware
Apr 16, 2026
Jul 11, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.
1Cisco
1Cbos
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.
1Cisco
1Catos
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.
1Cisco
1Vpn 3000 Concentrator Series Software
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.
1Cisco
1Aironet 340
Apr 16, 2026
Jun 27, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.
1Cisco
6Vpn 3000 Concentrator
Vpn 3005 ConcentratorVpn 3015 Concentrator+3 more
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disco...Show more
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.Show less
1Cisco
3Content Services Switch 11050
Content Services Switch 11150Content Services Switch 11800
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.