Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-01-15 CVE-2012-1316 Improper Certificate Validation vulnerability in Cisco Ironport web Security Appliance
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
network
cisco CWE-295
4.3
2020-01-15 CVE-2012-0334 Improper Input Validation vulnerability in Cisco Ironport web Security Appliance
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks
high complexity
cisco CWE-20
3.2
2020-01-07 CVE-2013-5122 Improper Authentication vulnerability in Cisco products
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access
network
low complexity
cisco CWE-287
critical
10.0
2020-01-06 CVE-2019-15999 Unspecified vulnerability in Cisco Data Center Network Manager
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device.
network
low complexity
cisco
4.0
2020-01-06 CVE-2019-15985 SQL Injection vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device.
network
low complexity
cisco CWE-89
critical
9.0
2020-01-06 CVE-2019-15984 SQL Injection vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device.
network
low complexity
cisco CWE-89
7.2
2020-01-06 CVE-2019-15983 XXE vulnerability in Cisco Data Center Network Manager
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
4.0
2020-01-06 CVE-2019-15982 Path Traversal vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
critical
9.0
2020-01-06 CVE-2019-15981 Path Traversal vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
critical
9.0
2020-01-06 CVE-2019-15980 Path Traversal vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device.
network
low complexity
cisco CWE-22
critical
9.0