Vulnerabilities > Cisco > IOS > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-12670 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco IOS 16.10.1
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device.
local
low complexity
cisco CWE-732
4.6
2019-09-25 CVE-2019-12665 Unspecified vulnerability in Cisco IOS 15.6(2)T/Fd1.5.0
A vulnerability in the HTTP client feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to read and modify data that should normally have been sent via an encrypted channel.
network
cisco
5.8
2019-09-25 CVE-2019-12656 Improper Input Validation vulnerability in Cisco products
A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.0
2019-05-13 CVE-2019-1649 Improper Locking vulnerability in Cisco products
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component.
local
low complexity
cisco CWE-667
6.7
2019-03-28 CVE-2019-1757 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate.
network
high complexity
cisco CWE-295
5.9
2019-03-28 CVE-2019-1747 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
5.0
2019-03-28 CVE-2019-1746 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2019-01-10 CVE-2018-0484 Unspecified vulnerability in Cisco IOS 16.6.2/16.6.4
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration.
network
low complexity
cisco
4.0
2018-10-05 CVE-2018-15373 Allocation of Resources Without Limits or Throttling vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-770
6.1
2018-10-05 CVE-2018-0475 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1