Cisco Intrusion Prevention System vulnerabilities
11 known vulnerabilities affecting cisco/intrusion_prevention_system.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2015-0654HIGHCVSS 7.1v7.2\(1\)e4v7.2\(2\)e4+1 more2015-03-13
CVE-2015-0654 [HIGH] CWE-362 CVE-2015-0654: Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion P
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.
nvd
CVE-2014-3406HIGHCVSS 7.1≤ 7.1\(7\)e42014-10-19
CVE-2014-3406 [HIGH] CWE-362 CVE-2014-3406: Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
nvd
CVE-2014-3402MEDIUMCVSS 5.0≤ 7.0\(8\)e4v7.0+8 more2014-10-10
CVE-2014-3402 [MEDIUM] CWE-287 CVE-2014-3402: The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug
nvd
CVE-2014-2103MEDIUMCVSS 6.8v5.1v6.0+13 more2014-02-27
CVE-2014-2103 [MEDIUM] CWE-20 CVE-2014-2103: Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of servic
Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.
nvd
CVE-2013-1243HIGHCVSS 7.8≤ 7.12013-07-18
CVE-2013-1243 [HIGH] CWE-119 CVE-2013-1243: The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and
The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID CSCtx18596.
nvd
CVE-2013-3410HIGHCVSS 7.8≤ 7.0\(8\)e4v7.0+8 more2013-07-18
CVE-2013-3410 [HIGH] CWE-119 CVE-2013-3410: Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote at
Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation, aka Bug ID CSCua61977.
nvd
CVE-2013-1218HIGHCVSS 7.8≤ 7.12013-07-18
CVE-2013-1218 [HIGH] CWE-119 CVE-2013-1218: Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7
Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.
nvd
CVE-2012-3899MEDIUMCVSS 5.0v6.0v6.2+1 more2012-09-16
CVE-2012-3899 [MEDIUM] CWE-399 CVE-2012-3899: sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, whic
sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.
nvd
CVE-2012-3901MEDIUMCVSS 5.0v7.0v7.12012-09-16
CVE-2012-3901 [MEDIUM] CWE-119 CVE-2012-3901: The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote atta
The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.
nvd
CVE-2011-4022MEDIUMCVSS 5.0v7.0v7.12012-05-03
CVE-2011-4022 [MEDIUM] CWE-287 CVE-2011-4022: The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a
The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.
nvd
CVE-2008-2060HIGHCVSS 7.8v5.1v6.02008-06-18
CVE-2008-2060 [HIGH] CWE-16 CVE-2008-2060: Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x bef
Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a "specific series of jumbo Ethernet frames."
nvd