Vulnerabilities > Cisco > IOS > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-08-31 CVE-2007-4632 Improper Authentication vulnerability in Cisco IOS 12.2E/12.2F/12.2S
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.
high complexity
cisco CWE-287
4.3
2007-08-20 CVE-2007-4430 Improper Input Validation vulnerability in Cisco products
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command.
network
low complexity
cisco CWE-20
5.0
2007-08-09 CVE-2007-4295 Voice vulnerability in Cisco IOS and Unified Communications Manager
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80749.
network
cisco
6.8
2007-08-09 CVE-2007-4294 Voice vulnerability in Cisco Unified Communications Manager 5.0/5.1/6.0
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
network
cisco
6.8
2007-05-10 CVE-2007-2587 Multiple vulnerability in Cisco IOS FTP Server
The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).
network
cisco
6.3
2007-03-03 CVE-2007-1258 Denial-Of-Service vulnerability in IOS
Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.
low complexity
cisco
6.1
2007-02-14 CVE-2007-0917 Multiple vulnerability in Cisco IOS Intrusion Prevention System
The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.
network
low complexity
cisco
6.4
2007-01-11 CVE-2007-0199 Denial Of Service vulnerability in Cisco IOS Data-link Switching
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message...
network
low complexity
cisco
5.0
2006-02-01 CVE-2006-0486 Local Security vulnerability in Cisco IOS 12.2(25)S/12.3T/12.4
Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.
local
low complexity
cisco
4.6
2006-02-01 CVE-2006-0485 Unspecified vulnerability in Cisco IOS
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.
local
low complexity
cisco
4.6