Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-05-03 CVE-2019-1693 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
6.5
2019-05-03 CVE-2019-1692 Information Exposure vulnerability in Cisco Application Policy Infrastructure Controller 4.1(0.88A)/8.3(1)S6
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information.
network
low complexity
cisco CWE-200
5.0
2019-05-03 CVE-2019-1687 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the TCP proxy functionality for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2019-05-03 CVE-2019-1682 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 3.2(2L)
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device.
local
low complexity
cisco CWE-264
7.2
2019-05-03 CVE-2019-1635 Improper Handling of Exceptional Conditions vulnerability in Cisco products
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.8
2019-05-03 CVE-2019-1592 Improper Input Validation vulnerability in Cisco Nx-Os 14.1(0.90)
A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affected device.
local
low complexity
cisco CWE-20
7.2
2019-05-03 CVE-2019-1590 Improper Certificate Validation vulnerability in Cisco Nx-Os 14.1(0.90)/8.3(0)Sk(0.39)
A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to perform insecure TLS client authentication on an affected device.
network
cisco CWE-295
6.8
2019-05-03 CVE-2019-1589 Information Exposure vulnerability in Cisco Nx-Os 8.3(0)Sk(0.39)
A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, local attacker with physical access to view sensitive information on an affected device.
local
low complexity
cisco CWE-200
2.1
2019-05-03 CVE-2019-1587 Resource Management Errors vulnerability in Cisco Nx-Os 8.3(0)Sk(0.39)
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information.
network
low complexity
cisco CWE-399
4.0
2019-05-03 CVE-2019-1586 Incomplete Cleanup vulnerability in Cisco Application Policy Infrastructure Controller 4.1(0.90A)
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device.
local
low complexity
cisco CWE-459
2.1