Vulnerabilities > Cisco > IOS XE > 16.7.1a

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-1755 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user.
network
low complexity
cisco CWE-20
critical
9.0
2019-03-28 CVE-2019-1754 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI.
network
low complexity
cisco CWE-20
critical
9.0
2019-03-28 CVE-2019-1753 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI.
network
low complexity
cisco CWE-20
critical
9.0
2019-03-28 CVE-2019-1752 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1745 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges.
local
low complexity
cisco CWE-78
7.2
2019-03-28 CVE-2019-1743 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1742 Improper Access Control vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information.
network
low complexity
cisco CWE-284
5.0
2019-03-28 CVE-2019-1741 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.8