Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2017-12303

A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types....

5.3CVSS

5.4AI Score

0.001EPSS

2017-11-16 07:29 AM
46
cve
cve

CVE-2017-12304

A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface on an affected device. The vulnerability is du...

6.1CVSS

6AI Score

0.001EPSS

2017-11-16 07:29 AM
35
2
cve
cve

CVE-2017-12305

A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticati...

6.7CVSS

6.8AI Score

0.001EPSS

2017-11-16 07:29 AM
40
cve
cve

CVE-2017-12306

A vulnerability in the upgrade process of Cisco Spark Board could allow an authenticated, local attacker to install an unverified upgrade package, aka Signature Verification Bypass. The vulnerability is due to insufficient upgrade package validation. An attacker could exploit this vulnerability by ...

4.4CVSS

4.6AI Score

0.0004EPSS

2017-11-16 07:29 AM
26
2
cve
cve

CVE-2017-12307

A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input v...

6.1CVSS

6AI Score

0.001EPSS

2018-01-18 06:29 AM
37
cve
cve

CVE-2017-12308

A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of...

6.1CVSS

6.6AI Score

0.001EPSS

2018-01-18 06:29 AM
38
cve
cve

CVE-2017-12309

A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a HTTP response splitting attack. The vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker could exploit this vu...

5.3CVSS

5.2AI Score

0.001EPSS

2017-11-16 07:29 AM
55
2
cve
cve

CVE-2017-12310

A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional reconnaissance attacks...

7.5CVSS

7.3AI Score

0.002EPSS

2018-03-27 09:29 AM
25
cve
cve

CVE-2017-12311

A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal H.264 frame. The vulnerability is triggered by an H.264 frame that has an invalid p...

5.8CVSS

5.7AI Score

0.002EPSS

2017-11-16 07:29 AM
34
cve
cve

CVE-2017-12312

An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory wher...

6.7CVSS

6.8AI Score

0.001EPSS

2017-11-16 07:29 AM
41
cve
cve

CVE-2017-12313

An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working director...

6.7CVSS

6.8AI Score

0.001EPSS

2017-11-16 07:29 AM
30
cve
cve

CVE-2017-12314

A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to the device availability, confidentiality, and integrity, aka Insecure Library Loading. The vulnerability is due to t...

7.8CVSS

7.2AI Score

0.0004EPSS

2017-11-16 07:29 AM
26
cve
cve

CVE-2017-12315

A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system log files. The attacker would have to be authenticated as an administrative user ...

6CVSS

5.6AI Score

0.0004EPSS

2017-11-16 07:29 AM
35
2
cve
cve

CVE-2017-12316

A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side login attempt limit enforce...

7.5CVSS

7.6AI Score

0.001EPSS

2017-11-16 07:29 AM
28
2
cve
cve

CVE-2017-12317

The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker c...

6.7CVSS

6.3AI Score

0.0004EPSS

2017-10-22 06:29 PM
32
2
cve
cve

CVE-2017-12318

A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of service (DoS) condition. The vulnerability is ...

7.5CVSS

7.6AI Score

0.001EPSS

2017-11-16 07:29 AM
35
cve
cve

CVE-2017-12319

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing tabl...

5.9CVSS

5.8AI Score

0.001EPSS

2018-03-27 09:29 AM
838
In Wild
cve
cve

CVE-2017-12320

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are ...

6.1CVSS

6.1AI Score

0.001EPSS

2017-11-16 07:29 AM
26
cve
cve

CVE-2017-12321

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are ...

6.1CVSS

6.1AI Score

0.001EPSS

2017-11-16 07:29 AM
25
cve
cve

CVE-2017-12322

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are ...

6.1CVSS

6.1AI Score

0.001EPSS

2017-11-16 07:29 AM
25
cve
cve

CVE-2017-12323

Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undesired web page. The vulnerabilities are ...

6.1CVSS

6.1AI Score

0.001EPSS

2017-11-16 07:29 AM
28
cve
cve

CVE-2017-12328

A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the SIP process unexpectedly restarts. All active phone calls are dropped as the SIP process ...

5.8CVSS

5.8AI Score

0.002EPSS

2017-11-30 09:29 AM
44
cve
cve

CVE-2017-12329

A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacke...

6.3CVSS

6.8AI Score

0.0004EPSS

2017-11-30 09:29 AM
31
cve
cve

CVE-2017-12330

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting c...

6.3CVSS

6.8AI Score

0.0004EPSS

2017-11-30 09:29 AM
33
cve
cve

CVE-2017-12331

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software patch. The vulnerability is due to insufficient NX-OS signature verification for software patches. An authenticated, local attacker could exploit this...

6.7CVSS

6.3AI Score

0.0004EPSS

2017-11-30 09:29 AM
27
cve
cve

CVE-2017-12332

A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this vulnerability by installing ...

4.4CVSS

4.6AI Score

0.0004EPSS

2017-11-30 09:29 AM
31
cve
cve

CVE-2017-12333

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this ...

6.7CVSS

6.3AI Score

0.0004EPSS

2017-11-30 09:29 AM
29
cve
cve

CVE-2017-12334

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation of command argument...

6.7CVSS

6.9AI Score

0.0004EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12335

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by injecting crafted command arg...

6.3CVSS

6.9AI Score

0.0004EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12336

A vulnerability in the TCL scripting subsystem of Cisco NX-OS System Software could allow an authenticated, local attacker to escape the interactive TCL shell and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient input validation...

4.2CVSS

5.1AI Score

0.0004EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12337

A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or P...

9.8CVSS

9.4AI Score

0.038EPSS

2017-11-16 07:29 AM
37
cve
cve

CVE-2017-12338

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The vulnerability is due to insufficient input validation for a specific CLI command. An attacker could exploit this vulnerability by issuing a crafted com...

6CVSS

5.8AI Score

0.0004EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12339

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could exploit this vulnerability by injecting c...

5.7CVSS

6.3AI Score

0.0004EPSS

2017-11-30 09:29 AM
29
cve
cve

CVE-2017-12340

A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell of an affected device's operating system, even if the Bash s...

4.2CVSS

4.5AI Score

0.0004EPSS

2017-11-30 09:29 AM
35
cve
cve

CVE-2017-12341

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficient input validation during the installa...

6.7CVSS

6.9AI Score

0.0004EPSS

2017-11-30 09:29 AM
29
cve
cve

CVE-2017-12342

A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow an unauthenticated, local attacker to read and send packets outside the scope of the OAC. The vulnerability is due to insufficient internal security measures in the OAC feature. An attacker could ex...

6.8CVSS

6.5AI Score

0.001EPSS

2017-11-30 09:29 AM
36
cve
cve

CVE-2017-12343

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting...

8.8CVSS

7.7AI Score

0.002EPSS

2017-11-30 09:29 AM
34
cve
cve

CVE-2017-12344

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting...

6.1CVSS

6AI Score

0.001EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12345

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting...

4.7CVSS

4.7AI Score

0.001EPSS

2017-11-30 09:29 AM
33
cve
cve

CVE-2017-12346

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting...

6.1CVSS

6AI Score

0.001EPSS

2017-11-30 09:29 AM
30
cve
cve

CVE-2017-12347

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client interface, or conduct a cross-site scripting...

6.1CVSS

6AI Score

0.001EPSS

2017-11-30 09:29 AM
28
cve
cve

CVE-2017-12348

Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf...

5.4CVSS

5.3AI Score

0.001EPSS

2017-11-30 09:29 AM
29
cve
cve

CVE-2017-12349

Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of the affected interface. Cisco Bug IDs: CSCvf...

5.4CVSS

5.3AI Score

0.001EPSS

2017-11-30 09:29 AM
26
cve
cve

CVE-2017-12350

A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user credentials for an affected virtual applianc...

8.2CVSS

7.9AI Score

0.0004EPSS

2017-11-16 07:29 AM
41
cve
cve

CVE-2017-12351

A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perform this attack. The vulnerability is due to ...

5.7CVSS

5.4AI Score

0.0004EPSS

2017-11-30 09:29 AM
35
cve
cve

CVE-2017-12352

A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system. Th...

6.7CVSS

6.9AI Score

0.0004EPSS

2017-11-30 09:29 AM
31
cve
cve

CVE-2017-12353

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to improper error handling of a m...

5.8CVSS

5.7AI Score

0.002EPSS

2017-11-30 09:29 AM
35
cve
cve

CVE-2017-12354

A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect system software version in...

5.3CVSS

5.1AI Score

0.001EPSS

2017-11-30 09:29 AM
33
cve
cve

CVE-2017-12355

A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly, resulting in a brief denial of service (DoS...

5.3CVSS

5.5AI Score

0.002EPSS

2017-11-30 09:29 AM
30
cve
cve

CVE-2017-12356

A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is du...

6.1CVSS

5.8AI Score

0.001EPSS

2017-11-30 09:29 AM
59
Total number of security vulnerabilities6090