Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-09-05 CVE-2019-12635 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Content Security Management Appliance
A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email.
network
low complexity
cisco CWE-732
4.3
2019-09-05 CVE-2019-12633 Server-Side Request Forgery (SSRF) vulnerability in Cisco Unified Contact Center Express
A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system.
network
low complexity
cisco CWE-918
7.5
2019-09-05 CVE-2019-12632 Server-Side Request Forgery (SSRF) vulnerability in Cisco Finesse 11.6(1)/12.0(1)/12.5(1)
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system.
network
low complexity
cisco CWE-918
7.5
2019-08-30 CVE-2019-1977 State Issues vulnerability in Cisco Nx-Os
A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances.
network
low complexity
cisco CWE-371
7.5
2019-08-30 CVE-2019-1969 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic.
network
low complexity
cisco CWE-20
5.3
2019-08-30 CVE-2019-1968 Improper Encoding or Escaping of Output vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart.
network
low complexity
cisco CWE-116
7.5
2019-08-30 CVE-2019-1967 Resource Exhaustion vulnerability in Cisco Nx-Os
A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
7.5
2019-08-30 CVE-2019-1966 Unspecified vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device.
local
low complexity
cisco
7.8
2019-08-28 CVE-2019-1965 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Nx-Os
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination.
network
low complexity
cisco CWE-772
7.7
2019-08-28 CVE-2019-1964 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an unexpected restart of the netstack process on an affected device.
network
low complexity
cisco CWE-20
7.5