Cisco
cisco
6,622 CVEs • 6,224 products
Products (6,224)
Click to collapseToggle
Products (6,224)
Click to collapse
CVEs (6,622)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Broadband Operating System Cisco 6xx RoutersApr 16, 2026 Feb 16, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. |
1Cisco 2Broadband Operating System Cisco 6xx RoutersApr 16, 2026 Feb 16, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. |
The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. |
1Cisco 2Broadband Operating System Cisco 6xx RoutersApr 16, 2026 Feb 16, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. |
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. |
1Cisco 3Catalyst 4000 Catalyst 5000Catalyst 6000Apr 16, 2026 Feb 12, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error. |
1Cisco 2Arrowpoint Content Services SwitchApr 16, 2026 Feb 12, 2001 N/A· v4 N/A· v3 2.1 LOW· v2 Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. |
1Cisco 2Arrowpoint Content Services SwitchApr 16, 2026 Feb 12, 2001 N/A· v4 N/A· v3 2.1 LOW· v2 Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" comman...Show more |
1Cisco 1Sn 5420 Storage Router Firmware Apr 16, 2026 Jan 8, 2001 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. |
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections. |
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. |
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. |
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges. |
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory. |
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords. |
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. |
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet. |
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive...Show more |
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before send...Show more |
1Cisco 4Gigabit Switch Router 12008 Gigabit Switch Router 12012Gigabit Switch Router 12016+1 moreApr 16, 2026 Oct 20, 2000 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote...Show more |