Vulnerabilities > Cisco > IOS > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-12655 Classic Buffer Overflow vulnerability in Cisco IOS
A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT IPv6 to IPv4 (NAT64), and the Zone-Based Policy Firewall (ZBFW) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-120
7.5
2019-09-25 CVE-2019-12652 Unspecified vulnerability in Cisco IOS 15.2(3)E1/15.2(4)E3
A vulnerability in the ingress packet processing function of Cisco IOS Software for Cisco Catalyst 4000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2019-09-25 CVE-2019-12651 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
8.8
2019-09-25 CVE-2019-12650 OS Command Injection vulnerability in Cisco IOS and IOS XE
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
8.8
2019-09-25 CVE-2019-12648 Incorrect Authorization vulnerability in Cisco IOS 15.7(3)M3
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device.
network
low complexity
cisco CWE-863
8.8
2019-03-28 CVE-2019-1756 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
network
low complexity
cisco CWE-20
7.2
2019-03-28 CVE-2019-1752 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1751 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to cause either an interface queue wedge or a device reload.
network
low complexity
cisco CWE-20
7.5
2019-03-28 CVE-2019-1748 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.
network
high complexity
cisco CWE-295
7.4
2019-03-28 CVE-2019-1747 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
8.6