Vulnerabilities > Cisco > IOS XE > 3.2.0ja

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-1756 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
network
low complexity
cisco CWE-20
7.2
2019-03-28 CVE-2019-1755 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user.
network
low complexity
cisco CWE-20
7.2
2019-03-28 CVE-2019-1754 Improper Privilege Management vulnerability in Cisco IOS XE
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI.
network
low complexity
cisco CWE-269
8.8
2019-03-28 CVE-2019-1753 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI.
network
low complexity
cisco CWE-20
8.8
2019-03-28 CVE-2019-1742 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information.
network
low complexity
cisco
5.3
2019-03-28 CVE-2019-1741 Use After Free vulnerability in Cisco IOS XE
A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-416
7.5
2019-03-28 CVE-2019-1740 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-20
8.6
2019-03-28 CVE-2019-1739 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1738 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-20
7.5
2018-10-05 CVE-2018-0197 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the internal VTP database on an affected device and cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5