Vulnerabilities > Cisco > Intrusion Prevention System

DATE CVE VULNERABILITY TITLE RISK
2015-03-13 CVE-2015-0654 Race Condition vulnerability in Cisco Intrusion Prevention System 7.2(1)E4/7.2(2)E4/7.3(2)E4
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.
network
cisco CWE-362
7.1
2014-10-19 CVE-2014-3406 Race Condition vulnerability in Cisco Intrusion Prevention System
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
network
cisco CWE-362
7.1
2014-10-10 CVE-2014-3402 Improper Authentication vulnerability in Cisco Intrusion Prevention System
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.
network
low complexity
cisco CWE-287
5.0
2014-02-27 CVE-2014-2103 Improper Input Validation vulnerability in Cisco Intrusion Prevention System
Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.
network
low complexity
cisco CWE-20
6.8
2013-09-19 CVE-2013-5497 Improper Authentication vulnerability in Cisco Intrusion Prevention System
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.
network
cisco CWE-287
4.3
2013-07-18 CVE-2013-3411 Denial of Service vulnerability in Cisco IPS Software
The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to cause a denial of service (device hang) via malformed IPv4 TCP packets, aka Bug ID CSCuh27460.
network
low complexity
cisco
7.8
2013-07-18 CVE-2013-3410 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco Intrusion Prevention System and IPS NME
Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation, aka Bug ID CSCua61977.
network
low complexity
cisco CWE-119
7.8
2013-07-18 CVE-2013-1243 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID CSCtx18596.
network
low complexity
cisco CWE-119
7.8
2013-07-18 CVE-2013-1218 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.
network
low complexity
cisco CWE-119
7.8
2013-04-29 CVE-2013-1219 Local Denial of Service vulnerability in Cisco Intrusion Prevention System
SensorApp in Cisco Intrusion Prevention System (IPS) allows local users to cause a denial of service (Regex hardware job failure and application hang) via a (1) initiate signature upgrade, (2) initiate global correlation, (3) show statistics anomaly-detection, or (4) clear database action, aka Bug ID CSCuc74630.
local
cisco
4.4