Vulnerabilities > Cisco > IOS > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-08-14 CVE-2018-0131 Inadequate Encryption Strength vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session.
network
high complexity
cisco CWE-326
5.9
2018-03-28 CVE-2018-0180 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
network
high complexity
cisco
5.9
2018-03-28 CVE-2018-0179 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
network
high complexity
cisco
5.9
2018-03-28 CVE-2018-0163 Improper Authentication vulnerability in Cisco IOS
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port.
low complexity
cisco CWE-287
6.5
2018-03-28 CVE-2018-0161 Unspecified vulnerability in Cisco IOS 15.2(5)E
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability.
network
high complexity
cisco
6.3
2018-03-27 CVE-2017-12319 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
network
high complexity
cisco
5.9
2018-02-08 CVE-2018-0123 Path Traversal vulnerability in Cisco IOS and IOS XE
A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files.
local
low complexity
cisco CWE-22
5.5
2017-11-16 CVE-2017-12304 Cross-site Scripting vulnerability in Cisco IOS 15.7(2.0Z)M
A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface on an affected device.
network
low complexity
cisco CWE-79
6.1
2017-10-19 CVE-2017-12289 Information Exposure vulnerability in Cisco IOS
A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an authenticated, local attacker to display sensitive IPsec information in the system log file.
local
low complexity
cisco CWE-200
4.4
2017-09-29 CVE-2017-12238 Unspecified vulnerability in Cisco IOS
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition.
low complexity
cisco
6.5