Vulnerabilities > Cisco > IOS XE > 16.3.6

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-1761 Improper Initialization vulnerability in Cisco IOS XE
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device.
low complexity
cisco CWE-665
3.3
2019-03-28 CVE-2019-1760 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload.
network
cisco CWE-20
7.1
2019-03-28 CVE-2019-1759 Improper Access Control vulnerability in Cisco IOS XE
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface.
network
low complexity
cisco CWE-284
5.0
2019-03-28 CVE-2019-1757 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate.
network
high complexity
cisco CWE-295
5.9
2019-03-28 CVE-2019-1755 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user.
network
low complexity
cisco CWE-20
critical
9.0
2019-03-28 CVE-2019-1752 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1745 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges.
local
low complexity
cisco CWE-78
7.2
2019-03-28 CVE-2019-1743 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1742 Improper Access Control vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information.
network
low complexity
cisco CWE-284
5.0
2017-09-29 CVE-2017-12239 Use of Hard-coded Credentials vulnerability in Cisco IOS XE
A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system.
local
low complexity
cisco CWE-798
7.2