cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-20508,https://securityvulnerability.io/vulnerability/CVE-2024-20508,Cisco UTD Snort IPS Engine Vulnerability Could Allow Bypass of Security Policies or Denial of Service,"A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort IPS Engine. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process. If the action in case of Cisco UTD Snort IPS Engine failure is set to the default, fail-open, successful exploitation of this vulnerability could allow the attacker to bypass configured security policies. If the action in case of Cisco UTD Snort IPS Engine failure is set to fail-close, successful exploitation of this vulnerability could cause traffic that is configured to be inspected by Cisco UTD Snort IPS Engine to be dropped.",Cisco,Unified Threat Defense Snort Intrusion Prevention System Engine,6.5,MEDIUM,0.0004600000102072954,false,,false,false,false,,,false,false,,2024-09-25T17:15:00.000Z,0 CVE-2017-3842,https://securityvulnerability.io/vulnerability/CVE-2017-3842,,"A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Known Affected Releases: 7.2(1)V7.",Cisco,Cisco Intrusion Prevention System Device Manager,5.3,MEDIUM,0.0026400000788271427,false,,false,false,false,,,false,false,,2017-02-22T02:00:00.000Z,0 CVE-2015-0654,https://securityvulnerability.io/vulnerability/CVE-2015-0654,,"Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.",Cisco,Intrusion Prevention System,,,0.0018599999602884054,false,,false,false,false,,,false,false,,2015-03-13T01:00:00.000Z,0 CVE-2014-3406,https://securityvulnerability.io/vulnerability/CVE-2014-3406,,"Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.",Cisco,Intrusion Prevention System,,,0.0018599999602884054,false,,false,false,false,,,false,false,,2014-10-19T01:00:00.000Z,0 CVE-2014-3402,https://securityvulnerability.io/vulnerability/CVE-2014-3402,,"The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.",Cisco,Intrusion Prevention System,,,0.0018599999602884054,false,,false,false,false,,,false,false,,2014-10-10T10:00:00.000Z,0 CVE-2014-2103,https://securityvulnerability.io/vulnerability/CVE-2014-2103,,"Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.",Cisco,Intrusion Prevention System,,,0.0010000000474974513,false,,false,false,false,,,false,false,,2014-02-27T20:00:00.000Z,0 CVE-2013-5497,https://securityvulnerability.io/vulnerability/CVE-2013-5497,,"The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.",Cisco,Intrusion Prevention System,,,0.008870000019669533,false,,false,false,false,,,false,false,,2013-09-19T18:00:00.000Z,0 CVE-2013-1243,https://securityvulnerability.io/vulnerability/CVE-2013-1243,,"The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID CSCtx18596.",Cisco,"Ips 4520 Sensor,Asa 5585-x,Ips 4345 Sensor,Ips Nme,Ips 4510 Sensor,Ips 4360 Sensor,Asa 5500-x Series Ips Ssp Software,Idsm-2,Intrusion Prevention System",,,0.001610000035725534,false,,false,false,false,,,false,false,,2013-07-18T12:48:00.000Z,0 CVE-2013-1218,https://securityvulnerability.io/vulnerability/CVE-2013-1218,,"Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.",Cisco,"Ips 4520 Sensor,Asa 5585-x,Ips 4345 Sensor,Ips Nme,Ips 4510 Sensor,Ips 4360 Sensor,Asa 5500-x Series Ips Ssp Software,Idsm-2,Intrusion Prevention System",,,0.001610000035725534,false,,false,false,false,,,false,false,,2013-07-18T12:48:00.000Z,0 CVE-2013-3410,https://securityvulnerability.io/vulnerability/CVE-2013-3410,,"Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation, aka Bug ID CSCua61977.",Cisco,"Intrusion Prevention System,Ips Nme",,,0.0018100000452250242,false,,false,false,false,,,false,false,,2013-07-18T00:00:00.000Z,0 CVE-2013-3411,https://securityvulnerability.io/vulnerability/CVE-2013-3411,,"The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to cause a denial of service (device hang) via malformed IPv4 TCP packets, aka Bug ID CSCuh27460.",Cisco,"Intrusion Prevention System,Idsm-2",,,0.0018100000452250242,false,,false,false,false,,,false,false,,2013-07-18T00:00:00.000Z,0 CVE-2013-1219,https://securityvulnerability.io/vulnerability/CVE-2013-1219,,"SensorApp in Cisco Intrusion Prevention System (IPS) allows local users to cause a denial of service (Regex hardware job failure and application hang) via a (1) initiate signature upgrade, (2) initiate global correlation, (3) show statistics anomaly-detection, or (4) clear database action, aka Bug ID CSCuc74630.",Cisco,Intrusion Prevention System,,,0.0007099999929778278,false,,false,false,false,,,false,false,,2013-04-29T12:20:00.000Z,0 CVE-2012-3899,https://securityvulnerability.io/vulnerability/CVE-2012-3899,,"sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.",Cisco,"Intrusion Prevention System,Ips 4240,Ips 4250 Sx,Ips 4255,Ips 4260,Ips 4270-20",,,0.001610000035725534,false,,false,false,false,,,false,false,,2012-09-16T10:34:00.000Z,0 CVE-2012-3901,https://securityvulnerability.io/vulnerability/CVE-2012-3901,,"The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.",Cisco,"Intrusion Prevention System,Ips 4240,Ips 4250 Sx,Ips 4255,Ips 4260,Ips 4270-20",,,0.0018100000452250242,false,,false,false,false,,,false,false,,2012-09-16T10:00:00.000Z,0 CVE-2011-4022,https://securityvulnerability.io/vulnerability/CVE-2011-4022,,"The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.",Cisco,Intrusion Prevention System,,,0.0018100000452250242,false,,false,false,false,,,false,false,,2012-05-03T10:11:00.000Z,0 CVE-2008-2060,https://securityvulnerability.io/vulnerability/CVE-2008-2060,,"Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a ""specific series of jumbo Ethernet frames.""",Cisco,Intrusion Prevention System,,,0.014159999787807465,false,,false,false,false,,,false,false,,2008-06-18T19:29:00.000Z,0