Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2018-0214

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this ...

5.3CVSS

6AI Score

0.001EPSS

2018-03-08 07:29 AM
29
cve
cve

CVE-2018-0215

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF prot...

6.3CVSS

6.6AI Score

0.001EPSS

2018-03-08 07:29 AM
34
cve
cve

CVE-2018-0216

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF prot...

5.4CVSS

5.8AI Score

0.001EPSS

2018-03-08 07:29 AM
36
cve
cve

CVE-2018-0217

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system. The vulnerability is due to insufficient validation of commands that are s...

6.7CVSS

6.9AI Score

0.001EPSS

2018-03-08 07:29 AM
29
cve
cve

CVE-2018-0218

A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (X...

3.3CVSS

4.2AI Score

0.002EPSS

2018-03-08 07:29 AM
40
cve
cve

CVE-2018-0219

A vulnerability in the web-based management interface of Cisco Unified Computing System (UCS) Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due ...

6.1CVSS

5.9AI Score

0.001EPSS

2018-03-08 07:29 AM
31
cve
cve

CVE-2018-0220

A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient val...

5.4CVSS

5.2AI Score

0.001EPSS

2018-03-08 07:29 AM
40
cve
cve

CVE-2018-0221

A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker needs valid administrator credentials fo...

6.7CVSS

6.8AI Score

0.001EPSS

2018-03-08 07:29 AM
35
cve
cve

CVE-2018-0222

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials. The vulnerability is due to the presence of undocumented, static user cred...

10CVSS

9.7AI Score

0.003EPSS

2018-05-17 03:29 AM
29
cve
cve

CVE-2018-0223

A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation o...

6.1CVSS

5.9AI Score

0.001EPSS

2018-03-08 07:29 AM
30
cve
cve

CVE-2018-0224

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system. The vulnerability is due to insufficient validation...

6.7CVSS

6.8AI Score

0.001EPSS

2018-03-08 07:29 AM
34
cve
cve

CVE-2018-0225

The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue.

9.8CVSS

9.5AI Score

0.001EPSS

2018-06-08 08:29 PM
29
cve
cve

CVE-2018-0226

A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticated, remote attacker to gain elevated privileges on an affecte...

7.5CVSS

7.7AI Score

0.003EPSS

2018-05-02 10:29 PM
35
cve
cve

CVE-2018-0227

A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification st...

7.5CVSS

8.1AI Score

0.001EPSS

2018-04-19 08:29 PM
40
2
cve
cve

CVE-2018-0228

A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due...

8.6CVSS

8.5AI Score

0.004EPSS

2018-04-19 08:29 PM
64
cve
cve

CVE-2018-0229

A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow a...

6.5CVSS

7.3AI Score

0.002EPSS

2018-04-19 08:29 PM
65
cve
cve

CVE-2018-0230

A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of servi...

8.6CVSS

8.4AI Score

0.001EPSS

2018-04-19 08:29 PM
71
cve
cve

CVE-2018-0231

A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) cond...

8.6CVSS

8.6AI Score

0.003EPSS

2018-04-19 08:29 PM
72
cve
cve

CVE-2018-0233

A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a de...

8.6CVSS

8.3AI Score

0.001EPSS

2018-04-19 08:29 PM
35
cve
cve

CVE-2018-0234

A vulnerability in the implementation of Point-to-Point Tunneling Protocol (PPTP) functionality in Cisco Aironet 1810, 1830, and 1850 Series Access Points could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vul...

8.6CVSS

7.6AI Score

0.003EPSS

2018-05-02 10:29 PM
31
cve
cve

CVE-2018-0235

A vulnerability in the 802.11 frame validation functionality of the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete inpu...

7.4CVSS

7.4AI Score

0.001EPSS

2018-05-02 10:29 PM
30
cve
cve

CVE-2018-0237

A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the software relies on only the file extension for detectin...

5.8CVSS

5.5AI Score

0.001EPSS

2018-04-19 08:29 PM
31
cve
cve

CVE-2018-0238

A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on a...

9.9CVSS

9.4AI Score

0.003EPSS

2018-04-19 08:29 PM
29
cve
cve

CVE-2018-0239

A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to cause an interface on the device to...

7.5CVSS

7.5AI Score

0.002EPSS

2018-04-19 08:29 PM
36
cve
cve

CVE-2018-0240

Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of ser...

8.6CVSS

8.5AI Score

0.002EPSS

2018-04-19 08:29 PM
55
3
cve
cve

CVE-2018-0241

A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IP...

7.4CVSS

7.5AI Score

0.001EPSS

2018-04-19 08:29 PM
39
cve
cve

CVE-2018-0242

A vulnerability in the WebVPN web-based management interface of Cisco Adaptive Security Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to in...

6.1CVSS

5.9AI Score

0.001EPSS

2018-04-19 08:29 PM
50
cve
cve

CVE-2018-0243

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy that is intended to drop the Server Message Block Version 2 (SMB2) and SMB Version 3 (SMB3) protocols if malware is detected. The vuln...

5.8CVSS

5.7AI Score

0.001EPSS

2018-04-19 08:29 PM
34
cve
cve

CVE-2018-0244

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured file action policy to drop the Server Message Block (SMB) protocol if a malware file is detected. The vulnerability is due to how the SMB protocol handle...

5.8CVSS

5.7AI Score

0.001EPSS

2018-04-19 08:29 PM
37
cve
cve

CVE-2018-0245

A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due to incomplete input and validation checking ...

5.3CVSS

5.3AI Score

0.001EPSS

2018-05-02 10:29 PM
45
cve
cve

CVE-2018-0247

A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerability is due to incorrect implementation ...

4.7CVSS

5AI Score

0.001EPSS

2018-05-02 10:29 PM
35
cve
cve

CVE-2018-0248

A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service ...

6.8CVSS

5.3AI Score

0.001EPSS

2019-04-17 10:29 PM
38
cve
cve

CVE-2018-0249

A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. A successful e...

4.3CVSS

4.8AI Score

0.001EPSS

2018-05-02 10:29 PM
41
cve
cve

CVE-2018-0250

A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The vulnerability i...

4.1CVSS

4.5AI Score

0.0004EPSS

2018-05-02 10:29 PM
26
cve
cve

CVE-2018-0251

A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of that portal o...

6.1CVSS

6AI Score

0.001EPSS

2018-04-19 08:29 PM
81
cve
cve

CVE-2018-0252

A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vul...

8.6CVSS

7.8AI Score

0.001EPSS

2018-05-02 10:29 PM
31
cve
cve

CVE-2018-0253

A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's privilege level. The vulnerability is d...

9.8CVSS

9.6AI Score

0.004EPSS

2018-05-02 10:29 PM
47
cve
cve

CVE-2018-0254

A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also configured. The vulnerability is due to incorrect ...

5.3CVSS

5.3AI Score

0.001EPSS

2018-04-19 08:29 PM
32
cve
cve

CVE-2018-0255

A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to insufficient CSRF protection by the devic...

8.8CVSS

8.8AI Score

0.001EPSS

2018-04-19 08:29 PM
61
cve
cve

CVE-2018-0256

A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote attacker to cause the Session Manager (SESSMGR) process on an affected device to restart, resulting in a denial of service (DoS) condition. The vulnerabil...

5.8CVSS

5.8AI Score

0.001EPSS

2018-04-19 08:29 PM
32
cve
cve

CVE-2018-0257

A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of c...

4.3CVSS

4.8AI Score

0.001EPSS

2018-04-19 08:29 PM
53
cve
cve

CVE-2018-0258

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects the following products: Cisco Prime Data ...

9.8CVSS

9.4AI Score

0.004EPSS

2018-05-02 10:29 PM
35
cve
cve

CVE-2018-0259

A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the ...

8.8CVSS

8.8AI Score

0.001EPSS

2018-04-19 08:29 PM
28
cve
cve

CVE-2018-0260

A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and download the contents of certain web application virtual directories. The vulnerability is due to lack of proper input validation and authorization of HTTP requests. An attacker could...

5.3CVSS

5.1AI Score

0.001EPSS

2018-04-19 08:29 PM
32
cve
cve

CVE-2018-0262

A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which c...

8.1CVSS

8.4AI Score

0.033EPSS

2018-05-02 10:29 PM
56
cve
cve

CVE-2018-0263

A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports o...

7.4CVSS

7.5AI Score

0.001EPSS

2018-06-07 12:29 PM
38
cve
cve

CVE-2018-0264

A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability by sending the user a link or email attachme...

9.6CVSS

9.3AI Score

0.007EPSS

2018-05-02 10:29 PM
332
cve
cve

CVE-2018-0266

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing ...

4.3CVSS

4.5AI Score

0.001EPSS

2018-04-19 08:29 PM
30
cve
cve

CVE-2018-0267

A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interf...

6.5CVSS

6.2AI Score

0.0004EPSS

2018-04-19 08:29 PM
51
cve
cve

CVE-2018-0268

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the Kubernetes container ...

10CVSS

9.8AI Score

0.002EPSS

2018-05-17 03:29 AM
29
Total number of security vulnerabilities6090