Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-11-26 CVE-2019-15967 Unspecified vulnerability in Cisco Roomos and Telepresence Collaboration Endpoint
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, local attacker to enable audio recording without notifying users.
local
low complexity
cisco
2.1
2019-11-26 CVE-2019-15960 Unspecified vulnerability in Cisco Webex Meetings
A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page.
network
low complexity
cisco
6.5
2019-11-26 CVE-2019-15958 Improper Input Validation vulnerability in Cisco Prime Infrastructure
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system.
network
low complexity
cisco CWE-20
critical
10.0
2019-11-26 CVE-2019-15956 Unspecified vulnerability in Cisco Asyncos and web Security Appliance
A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device.
network
low complexity
cisco
6.5
2019-11-26 CVE-2019-15288 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell.
network
low complexity
cisco CWE-20
6.5
2019-11-26 CVE-2019-15286 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
network
cisco CWE-119
critical
9.3
2019-11-26 CVE-2019-15284 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
network
cisco CWE-119
critical
9.3
2019-11-26 CVE-2019-15276 Improper Input Validation vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
4.0
2019-11-26 CVE-2019-15271 Deserialization of Untrusted Data vulnerability in Cisco products
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
network
low complexity
cisco CWE-502
critical
9.0
2019-11-05 CVE-2019-1982 Incorrect Default Permissions vulnerability in Cisco products
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections.
network
low complexity
cisco CWE-276
5.0