Skip to main content

Vendor archive

cisco CVEs

Beta · best-effort

6,619 CVEs tagged to vendor cisco574 Critical, 2,399 High, 3,567 Medium, 77 Low, 2 Unrated.

CVE-2002-1596

Published Jan 9, 2002

Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1597

Published Jan 9, 2002

Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1210

Published Dec 30, 2001

Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remo…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0861

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0862

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0863

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0864

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entrie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0865

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the int…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0866

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0867

Published Dec 6, 2001

Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0929

Published Nov 28, 2001

Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol ty…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0895

Published Nov 15, 2001

Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contain…

CVSS 5.0 · Medium

CVE-2001-0741

Published Oct 18, 2001

Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0750

Published Oct 18, 2001

Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0751

Published Oct 18, 2001

Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0752

Published Oct 18, 2001

Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0753

Published Oct 18, 2001

Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0754

Published Oct 18, 2001

Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and sto…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0757

Published Oct 18, 2001

Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0783

Published Oct 18, 2001

Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1098

Published Oct 10, 2001

Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1071

Published Oct 9, 2001

Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcemen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0650

Published Sep 20, 2001

Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1105

Published Sep 12, 2001

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authenticatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,526-6,550 of 6,619 CVEsPage 262 of 265