Vulnerabilities > Cisco > Elastic Services Controller > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-05-10 CVE-2019-1867 Improper Authentication vulnerability in Cisco Elastic Services Controller
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API.
network
low complexity
cisco CWE-287
critical
10.0
2018-02-22 CVE-2018-0121 Improper Authentication vulnerability in Cisco products
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system.
network
low complexity
cisco CWE-287
critical
9.8
2017-07-06 CVE-2017-6713 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Elastic Services Controller
A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system.
network
low complexity
cisco CWE-770
critical
9.8