Vendor CVEs
Cisco Systems, Inc.
All CVEs
6,958 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0621 | 0.00 | — | 0.01 | Aug 14, 2001 | The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands. | |||
| CVE-2001-1183 | 0.00 | — | 0.04 | Jul 12, 2001 | PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet. | |||
| CVE-2001-1038 | 0.00 | — | 0.02 | Jul 11, 2001 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023. | |||
| CVE-2001-0428 | 0.00 | — | 0.02 | Jul 2, 2001 | Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option. | |||
| CVE-2001-0429 | 0.00 | — | 0.01 | Jul 2, 2001 | Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service. | |||
| CVE-2001-0444 | 0.00 | — | 0.00 | Jul 2, 2001 | Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information. | |||
| CVE-2001-0455 | 0.00 | — | 0.02 | Jun 27, 2001 | Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration. | |||
| CVE-2001-0412 | 0.00 | — | 0.00 | Jun 18, 2001 | Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode. | |||
| CVE-2001-0427 | 0.00 | — | 0.03 | Jun 18, 2001 | Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts. | |||
| CVE-2000-0368 | 0.00 | — | 0.00 | Mar 12, 2001 | Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data. | |||
| CVE-2004-1776 | 0.00 | — | 0.03 | Feb 28, 2001 | Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard. | |||
| CVE-2001-1434 | 0.00 | — | 0.03 | Feb 28, 2001 | Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created. | |||
| CVE-2001-0057 | 0.00 | — | 0.01 | Feb 16, 2001 | Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. | |||
| CVE-2001-0055 | 0.00 | — | 0.01 | Feb 16, 2001 | CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. | |||
| CVE-2001-0058 | 0.00 | — | 0.02 | Feb 16, 2001 | The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character. | |||
| CVE-2001-0056 | 0.00 | — | 0.01 | Feb 16, 2001 | The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection. | |||
| CVE-2001-0019 | 0.00 | — | 0.00 | Feb 12, 2001 | Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands. | |||
| CVE-2001-0020 | 0.00 | — | 0.01 | Feb 12, 2001 | Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-2001-1037 | 0.00 | — | 0.00 | Jan 8, 2001 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. | |||
| CVE-2001-0161 | 0.00 | — | 0.01 | Jan 1, 2001 | Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. | |||
| CVE-2000-1056 | 0.00 | — | 0.02 | Dec 11, 2000 | CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords. | |||
| CVE-2000-1055 | 0.00 | — | 0.04 | Dec 11, 2000 | Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. | |||
| CVE-2000-0700 | 0.00 | — | 0.02 | Oct 20, 2000 | Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop… | |||
| CVE-2000-0486 | 0.00 | — | 0.02 | May 30, 2000 | Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field. | |||
| CVE-2000-0345 | 0.00 | — | 0.01 | May 3, 2000 | The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command. | |||
| CVE-2000-0268 | 0.00 | — | 0.02 | Apr 20, 2000 | Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot. | |||
| CVE-2000-0267 | 0.00 | — | 0.00 | Apr 20, 2000 | Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. | |||
| CVE-2000-0150 | 0.00 | — | 0.02 | Feb 12, 2000 | Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt. | |||
| CVE-1999-1465 | 0.00 | — | 0.02 | Dec 31, 1999 | Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as… | |||
| CVE-1999-1175 | 0.00 | — | 0.02 | Dec 31, 1999 | Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048. | |||
| CVE-1999-1126 | 0.00 | — | 0.00 | Dec 31, 1999 | Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3)… | |||
| CVE-1999-1100 | 0.00 | — | 0.01 | Dec 31, 1999 | Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force… | |||
| CVE-1999-1464 | 0.00 | — | 0.02 | Dec 31, 1999 | Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by… | |||
| CVE-1999-1042 | 0.00 | — | 0.00 | Dec 31, 1999 | Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings. | |||
| CVE-1999-1001 | 0.00 | — | 0.01 | Dec 16, 1999 | Cisco Cache Engine allows a remote attacker to gain access via a null username and password. | |||
| CVE-1999-0998 | 0.00 | — | 0.01 | Dec 16, 1999 | Cisco Cache Engine allows an attacker to replace content in the cache. | |||
| CVE-1999-1000 | 0.00 | — | 0.02 | Dec 16, 1999 | The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics. | |||
| CVE-1999-0843 | 0.00 | — | 0.01 | Nov 4, 1999 | Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port. | |||
| CVE-1999-1129 | 0.00 | — | 0.02 | Sep 1, 1999 | Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag. | |||
| CVE-1999-0734 | 0.00 | — | 0.01 | Aug 19, 1999 | A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication. | |||
| CVE-1999-0889 | 0.00 | — | 0.01 | Jul 1, 1999 | Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set. | |||
| CVE-1999-0775 | 0.00 | — | 0.03 | Jun 10, 1999 | Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. | |||
| CVE-1999-0445 | 0.00 | — | 0.01 | Apr 1, 1999 | In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. | |||
| CVE-1999-0415 | 0.00 | — | 0.01 | Mar 11, 1999 | The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. | |||
| CVE-1999-0222 | 0.00 | — | 0.01 | Mar 1, 1999 | Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. | |||
| CVE-1999-0430 | 0.00 | — | 0.02 | Mar 1, 1999 | Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload. | |||
| CVE-1999-0453 | 0.00 | — | 0.01 | Jan 1, 1999 | An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | |||
| CVE-1999-0162 | 0.00 | — | 0.02 | Sep 1, 1998 | The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. | |||
| CVE-1999-0158 | 0.00 | — | 0.01 | Aug 31, 1998 | Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known. | |||
| CVE-1999-0157 | 0.00 | — | 0.01 | Aug 18, 1998 | Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. |
- CVE-2001-0621Aug 14, 2001risk 0.00cvss —epss 0.01
The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.
- CVE-2001-1183Jul 12, 2001risk 0.00cvss —epss 0.04
PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.
- CVE-2001-1038Jul 11, 2001risk 0.00cvss —epss 0.02
Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.
- CVE-2001-0428Jul 2, 2001risk 0.00cvss —epss 0.02
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.
- CVE-2001-0429Jul 2, 2001risk 0.00cvss —epss 0.01
Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.
- CVE-2001-0444Jul 2, 2001risk 0.00cvss —epss 0.00
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.
- CVE-2001-0455Jun 27, 2001risk 0.00cvss —epss 0.02
Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.
- CVE-2001-0412Jun 18, 2001risk 0.00cvss —epss 0.00
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.
- CVE-2001-0427Jun 18, 2001risk 0.00cvss —epss 0.03
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.
- CVE-2000-0368Mar 12, 2001risk 0.00cvss —epss 0.00
Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.
- CVE-2004-1776Feb 28, 2001risk 0.00cvss —epss 0.03
Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.
- CVE-2001-1434Feb 28, 2001risk 0.00cvss —epss 0.03
Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.
- CVE-2001-0057Feb 16, 2001risk 0.00cvss —epss 0.01
Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.
- CVE-2001-0055Feb 16, 2001risk 0.00cvss —epss 0.01
CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.
- CVE-2001-0058Feb 16, 2001risk 0.00cvss —epss 0.02
The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.
- CVE-2001-0056Feb 16, 2001risk 0.00cvss —epss 0.01
The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.
- CVE-2001-0019Feb 12, 2001risk 0.00cvss —epss 0.00
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
- CVE-2001-0020Feb 12, 2001risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.
- CVE-2001-1037Jan 8, 2001risk 0.00cvss —epss 0.00
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged.
- CVE-2001-0161Jan 1, 2001risk 0.00cvss —epss 0.01
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.
- CVE-2000-1056Dec 11, 2000risk 0.00cvss —epss 0.02
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
- CVE-2000-1055Dec 11, 2000risk 0.00cvss —epss 0.04
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.
- CVE-2000-0700Oct 20, 2000risk 0.00cvss —epss 0.02
Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop…
- CVE-2000-0486May 30, 2000risk 0.00cvss —epss 0.02
Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.
- CVE-2000-0345May 3, 2000risk 0.00cvss —epss 0.01
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.
- CVE-2000-0268Apr 20, 2000risk 0.00cvss —epss 0.02
Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.
- CVE-2000-0267Apr 20, 2000risk 0.00cvss —epss 0.00
Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.
- CVE-2000-0150Feb 12, 2000risk 0.00cvss —epss 0.02
Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
- CVE-1999-1465Dec 31, 1999risk 0.00cvss —epss 0.02
Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as…
- CVE-1999-1175Dec 31, 1999risk 0.00cvss —epss 0.02
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.
- CVE-1999-1126Dec 31, 1999risk 0.00cvss —epss 0.00
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3)…
- CVE-1999-1100Dec 31, 1999risk 0.00cvss —epss 0.01
Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force…
- CVE-1999-1464Dec 31, 1999risk 0.00cvss —epss 0.02
Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by…
- CVE-1999-1042Dec 31, 1999risk 0.00cvss —epss 0.00
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
- CVE-1999-1001Dec 16, 1999risk 0.00cvss —epss 0.01
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
- CVE-1999-0998Dec 16, 1999risk 0.00cvss —epss 0.01
Cisco Cache Engine allows an attacker to replace content in the cache.
- CVE-1999-1000Dec 16, 1999risk 0.00cvss —epss 0.02
The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.
- CVE-1999-0843Nov 4, 1999risk 0.00cvss —epss 0.01
Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.
- CVE-1999-1129Sep 1, 1999risk 0.00cvss —epss 0.02
Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.
- CVE-1999-0734Aug 19, 1999risk 0.00cvss —epss 0.01
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
- CVE-1999-0889Jul 1, 1999risk 0.00cvss —epss 0.01
Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.
- CVE-1999-0775Jun 10, 1999risk 0.00cvss —epss 0.03
Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.
- CVE-1999-0445Apr 1, 1999risk 0.00cvss —epss 0.01
In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.
- CVE-1999-0415Mar 11, 1999risk 0.00cvss —epss 0.01
The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.
- CVE-1999-0222Mar 1, 1999risk 0.00cvss —epss 0.01
Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.
- CVE-1999-0430Mar 1, 1999risk 0.00cvss —epss 0.02
Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.
- CVE-1999-0453Jan 1, 1999risk 0.00cvss —epss 0.01
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
- CVE-1999-0162Sep 1, 1998risk 0.00cvss —epss 0.02
The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering.
- CVE-1999-0158Aug 31, 1998risk 0.00cvss —epss 0.01
Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
- CVE-1999-0157Aug 18, 1998risk 0.00cvss —epss 0.01
Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
Page 139 of 140