Skip over navigation
Home
Site Map
Search
Register
Sign In
Routeadmin
Home
Cisco Tech
Microsoft
VMware
Call Manager
Unity
UCCX
CCNA
Contact
Contact Us
your e-mail address
your name
subject
message
Cisco Systems
Feeds
Notices
Responses
Security Advisory
Cisco IOS XR Software Border Gateway Protocol Vulnerability
Thursday, September 02, 2010 12:30:00 AM
Cisco IOS XR Software contains a vulnerability in the Border Gateway Protocol (BGP) feature. The vulnerability manifests itself when a BGP peer announces a prefix with a specific, valid but unrecognized transitive attribute. On receipt of this prefix, the Cisco IOS XR device will corrupt the attribute before sending it to the neighboring devices. Neighboring devices that receive this corrupted update may reset the BGP peering session.
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Wednesday, August 25, 2010 1:40:00 AM
Cisco Unified Communications Manager contains two denial of service (DoS) vulnerabilities that affect the processing of Session Initiation Protocol (SIP) messages. Exploitation of these vulnerabilities could cause an interruption of voice services.
Cisco Unified Presence Denial of Service Vulnerabilities
Wednesday, August 25, 2010 1:30:00 AM
Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that affect the processing of Session Initiation Protocol (SIP) messages. Exploitation of these vulnerabilities could cause an interruption of presence services.
Cisco IOS Software TCP Denial of Service Vulnerability
Thursday, August 12, 2010 7:30:00 AM
Cisco IOS Software Release, 15.1(2)T is affected by a denial of service (DoS) vulnerability during the TCP establishment phase. The vulnerability could cause embryonic TCP connections to remain in a SYNRCVD or SYNSENT state. Enough embryonic TCP connections in these states could consume system resources and prevent an affected device from accepting or initiating new TCP connections, including any TCP-based remote management access to the device.
SQL Injection Vulnerability in Cisco Wireless Control System
Wednesday, August 11, 2010 2:00:00 AM
Cisco Wireless Control System (WCS) contains a SQL injection vulnerability that could allow an authenticated attacker full access to the vulnerable device, including modification of system configuration; create, modify and delete users; or modify the configuration of wireless devices managed by WCS.
Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine
Wednesday, August 11, 2010 2:00:00 AM
The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine contain the following DoS vulnerabilities: Real-Time Streaming Protocol (RTSP) inspection DoS vulnerability HTTP, RTSP, and Session Initiation Protocol (SIP) inspection DoS vulnerability Secure Socket Layer (SSL) DoS vulnerability SIP inspection DoS vulnerability
SNMP Version 3 Authentication Vulnerabilities
Monday, August 09, 2010 12:30:00 AM
Multiple Cisco products contain either of two authentication vulnerabilities in the Simple Network Management Protocol version 3 (SNMPv3) feature. These vulnerabilities can be exploited when processing a malformed SNMPv3 message. These vulnerabilities could allow the disclosure of network information or may enable an attacker to perform configuration changes to vulnerable devices. The SNMP server is an optional service that is disabled by default in Cisco products. Only SNMPv3 is impacted by these vulnerabilities. Workarounds are available for mitigating the impact of the vulnerabilities described in this document.
Multiple Vulnerabilities in Cisco Firewall Services Module
Wednesday, August 04, 2010 2:00:00 AM
Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Wednesday, August 04, 2010 2:00:00 AM
CDS Internet Streamer: Web Server Directory Traversal Vulnerability
Wednesday, July 28, 2010 11:00:00 PM
The Cisco Internet Streamer application, part of the Cisco Content Delivery System, contains a directory traversal vulnerability on its web server component that allows for arbitrary file access. By exploiting this vulnerability, an attacker may be able to read arbitrary files on the device, outside of the web server document directory, by using a specially crafted URL.
Page 1 of 2
1
2
>
>>