Vulnerabilities > Cisco > Energy Management Suite Software > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-08 CVE-2018-15445 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Energy Management Suite Software
A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.0
2018-11-08 CVE-2018-15444 XXE vulnerability in Cisco Energy Management Suite Software
A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
7.3