Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-12654 NULL Pointer Dereference vulnerability in Cisco IOS XE 15.6(1)S4.2/16.3.8/16.9.1
A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-476
7.5
2019-09-25 CVE-2019-12653 Improper Input Validation vulnerability in Cisco IOS XE 16.10.1/16.9
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2019-09-25 CVE-2019-12652 Unspecified vulnerability in Cisco IOS 15.2(3)E1/15.2(4)E3
A vulnerability in the ingress packet processing function of Cisco IOS Software for Cisco Catalyst 4000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2019-09-25 CVE-2019-12651 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
8.8
2019-09-25 CVE-2019-12650 OS Command Injection vulnerability in Cisco IOS and IOS XE
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
8.8
2019-09-25 CVE-2019-12649 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS and IOS XE
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device.
local
low complexity
cisco CWE-347
6.7
2019-09-25 CVE-2019-12648 Incorrect Authorization vulnerability in Cisco IOS 15.7(3)M3
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device.
network
low complexity
cisco CWE-863
8.8
2019-09-25 CVE-2019-12647 NULL Pointer Dereference vulnerability in Cisco IOS XE Fuji16.7.1/Fuji16.8.1
A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-476
7.5
2019-09-25 CVE-2019-12646 Improper Initialization vulnerability in Cisco IOS XE
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-665
7.5
2019-09-18 CVE-2019-1975 Improper Restriction of Rendered UI Layers or Frames vulnerability in Cisco products
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device.
network
low complexity
cisco CWE-1021
6.1