Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2018-0471

A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain...

7.4CVSS

7.3AI Score

0.001EPSS

2018-10-05 02:29 PM
38
cve
cve

CVE-2018-0472

A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to improper processing of malformed IPsec Au...

8.6CVSS

8.6AI Score

0.005EPSS

2018-10-05 02:29 PM
66
cve
cve

CVE-2018-0473

A vulnerability in the Precision Time Protocol (PTP) subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Precision Time Protocol. The vulnerability is due to insufficient processing of PTP packets. An attacker could exp...

8.6CVSS

8.4AI Score

0.002EPSS

2018-10-05 02:29 PM
66
cve
cve

CVE-2018-0474

A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An attacker could expl...

8.8CVSS

8.6AI Score

0.002EPSS

2019-01-10 04:29 PM
33
cve
cve

CVE-2018-0475

A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation when handling Cl...

7.4CVSS

7.4AI Score

0.001EPSS

2018-10-05 02:29 PM
82
cve
cve

CVE-2018-0476

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of SIP packets i...

5.9CVSS

5.9AI Score

0.003EPSS

2018-10-05 02:29 PM
63
cve
cve

CVE-2018-0477

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing...

6.7CVSS

7AI Score

0.0004EPSS

2018-10-05 02:29 PM
57
cve
cve

CVE-2018-0480

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdis...

6.1CVSS

6.2AI Score

0.001EPSS

2018-10-05 02:29 PM
55
cve
cve

CVE-2018-0481

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing...

6.7CVSS

7AI Score

0.0004EPSS

2018-10-05 02:29 PM
59
cve
cve

CVE-2018-0482

A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The vulnerability is due to insufficient valida...

5.4CVSS

5.2AI Score

0.001EPSS

2019-01-10 05:00 PM
40
cve
cve

CVE-2018-0483

A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied input of an affected client. An attacker cou...

5.4CVSS

5.2AI Score

0.001EPSS

2019-01-10 05:29 PM
40
cve
cve

CVE-2018-0484

A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to...

6.5CVSS

6.3AI Score

0.0005EPSS

2019-01-10 06:29 PM
69
cve
cve

CVE-2018-0485

A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/E3 module on the ISR4451-X to reload, result...

8.6CVSS

8.3AI Score

0.003EPSS

2018-10-05 02:29 PM
73
cve
cve

CVE-2018-15368

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly ...

6.7CVSS

6.9AI Score

0.0004EPSS

2018-10-05 02:29 PM
54
cve
cve

CVE-2018-15369

A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of crafted TACACS+ r...

6.8CVSS

6.7AI Score

0.001EPSS

2018-10-05 02:29 PM
59
cve
cve

CVE-2018-15370

A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, local attacker to bypass Cisco Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to the presence of a ...

6.8CVSS

6.6AI Score

0.001EPSS

2018-10-05 02:29 PM
45
cve
cve

CVE-2018-15371

A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authenti...

6.7CVSS

6.7AI Score

0.0004EPSS

2018-10-05 02:29 PM
86
cve
cve

CVE-2018-15372

A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected...

8.1CVSS

8.3AI Score

0.001EPSS

2018-10-05 02:29 PM
69
cve
cve

CVE-2018-15373

A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to im...

7.4CVSS

7.3AI Score

0.001EPSS

2018-10-05 02:29 PM
92
cve
cve

CVE-2018-15374

A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images ...

6.7CVSS

6.4AI Score

0.0004EPSS

2018-10-05 02:29 PM
57
cve
cve

CVE-2018-15375

A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the p...

6.7CVSS

6.6AI Score

0.0004EPSS

2018-10-05 02:29 PM
49
cve
cve

CVE-2018-15376

A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the p...

6.7CVSS

6.6AI Score

0.0004EPSS

2018-10-05 02:29 PM
56
cve
cve

CVE-2018-15377

A vulnerability in the Cisco Network Plug and Play agent, also referred to as the Cisco Open Plug-n-Play agent, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device. The vulnerability is due to insufficient inpu...

8.6CVSS

8.4AI Score

0.002EPSS

2018-10-05 02:29 PM
77
cve
cve

CVE-2018-15379

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This ...

9.8CVSS

9.6AI Score

0.967EPSS

2018-10-05 02:29 PM
65
cve
cve

CVE-2018-15380

A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting to the cluster ser...

8.8CVSS

8.8AI Score

0.001EPSS

2019-02-20 11:29 PM
23
cve
cve

CVE-2018-15381

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An atta...

9.8CVSS

9.9AI Score

0.594EPSS

2018-11-08 05:00 PM
25
cve
cve

CVE-2018-15382

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing key that is present in all Cisco HyperFlex systems. An attacker could exploit this vulnerability by accessing the static...

8.6CVSS

8.4AI Score

0.001EPSS

2018-10-05 02:29 PM
30
cve
cve

CVE-2018-15383

A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (D...

7.5CVSS

7.6AI Score

0.001EPSS

2018-10-05 02:29 PM
61
cve
cve

CVE-2018-15386

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to an insecure default configuration of the affected system. An ...

9.8CVSS

9.5AI Score

0.004EPSS

2018-10-05 02:29 PM
25
cve
cve

CVE-2018-15387

A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a cr...

9.8CVSS

9.2AI Score

0.002EPSS

2018-10-05 02:29 PM
42
cve
cve

CVE-2018-15388

A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processin...

8.6CVSS

8.4AI Score

0.002EPSS

2019-05-03 03:29 PM
36
cve
cve

CVE-2018-15389

A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are used during install. The vulnerability is due to a hard-coded ...

9.8CVSS

9.4AI Score

0.004EPSS

2018-10-05 02:29 PM
31
cve
cve

CVE-2018-15390

A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to rele...

6.8CVSS

6.9AI Score

0.001EPSS

2018-10-05 02:29 PM
31
cve
cve

CVE-2018-15391

A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could allow an unauthenticated, remote attacker to impact traffic passing through a device, potentially causing a denial of service (DoS) condition. The vulnerability is due to the affected software not valid...

7.5CVSS

7.6AI Score

0.002EPSS

2018-10-05 02:29 PM
49
cve
cve

CVE-2018-15392

A vulnerability in the DHCP service of Cisco Industrial Network Director could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of DHCP lease requests. An attacker could exploit this vulnerability by sending mali...

4.3CVSS

4.8AI Score

0.001EPSS

2018-10-05 02:29 PM
26
cve
cve

CVE-2018-15393

A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insuff...

6.1CVSS

5.9AI Score

0.001EPSS

2018-11-08 05:29 PM
33
cve
cve

CVE-2018-15394

A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system c...

9.8CVSS

10AI Score

0.001EPSS

2018-11-08 05:29 PM
27
cve
cve

CVE-2018-15395

A vulnerability in the authentication and authorization checking mechanisms of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, adjacent attacker to gain network access to a Cisco TrustSec domain. Under normal circumstances, this access should be prohibited. The vulnerabil...

5.4CVSS

5.5AI Score

0.001EPSS

2018-10-17 08:29 PM
34
cve
cve

CVE-2018-15396

A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size ...

6.8CVSS

6.6AI Score

0.001EPSS

2018-10-05 02:29 PM
37
cve
cve

CVE-2018-15397

A vulnerability in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpecte...

6.8CVSS

6.8AI Score

0.001EPSS

2018-10-05 02:29 PM
67
cve
cve

CVE-2018-15398

A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. Th...

4CVSS

4.6AI Score

0.001EPSS

2018-10-05 02:29 PM
50
cve
cve

CVE-2018-15399

A vulnerability in the TCP syslog module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust the 1550-byte buffers on an affected device, resulting in a denial of service (DoS) condition. Th...

6.8CVSS

6.7AI Score

0.001EPSS

2018-10-05 02:29 PM
60
cve
cve

CVE-2018-15400

A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insuffic...

6.1CVSS

5.9AI Score

0.001EPSS

2018-10-05 02:29 PM
33
cve
cve

CVE-2018-15401

A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficie...

6.5CVSS

6.7AI Score

0.001EPSS

2018-10-05 02:29 PM
33
cve
cve

CVE-2018-15402

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests within the management interface. An attack...

8.8CVSS

8.8AI Score

0.001EPSS

2018-10-17 08:29 PM
29
cve
cve

CVE-2018-15403

A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability...

5.4CVSS

5.3AI Score

0.001EPSS

2018-10-05 02:29 PM
34
cve
cve

CVE-2018-15404

A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size ...

6.5CVSS

6.5AI Score

0.001EPSS

2018-10-05 02:29 PM
31
cve
cve

CVE-2018-15405

A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to an authorization check that does not properly i...

6.5CVSS

6.3AI Score

0.001EPSS

2018-10-05 02:29 PM
41
cve
cve

CVE-2018-15406

A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient vali...

6.1CVSS

5.8AI Score

0.001EPSS

2018-10-05 02:29 PM
34
cve
cve

CVE-2018-15407

A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installa...

5.5CVSS

5.1AI Score

0.0004EPSS

2018-10-05 02:29 PM
29
Total number of security vulnerabilities6090