Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-05-03 CVE-2019-1844 Improper Input Validation vulnerability in Cisco Email Security Appliance 11.1.0131
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device.
network
low complexity
cisco CWE-20
5.3
2019-05-03 CVE-2019-1838 Cross-site Scripting vulnerability in Cisco Application Policy Infrastructure Controller 3.2(5D)/4.0(3D)
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
5.4
2019-05-03 CVE-2019-1836 Link Following vulnerability in Cisco Nx-Os 14.0(3D)
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files.
local
low complexity
cisco CWE-59
7.1
2019-05-03 CVE-2019-1817 Improper Input Validation vulnerability in Cisco web Security Appliance
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2019-05-03 CVE-2019-1816 Improper Input Validation vulnerability in Cisco web Security Appliance
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root.
local
low complexity
cisco CWE-20
7.8
2019-05-03 CVE-2019-1807 Session Fixation vulnerability in Cisco Umbrella
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session.
network
low complexity
cisco CWE-384
8.8
2019-05-03 CVE-2019-1804 Insecure Default Initialization of Resource vulnerability in Cisco products
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user.
network
low complexity
cisco CWE-1188
critical
9.8
2019-05-03 CVE-2019-1803 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Nexus 9000 Series Application Centric Infrastructure
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrator rights to gain elevated privileges as the root user on an affected device.
local
low complexity
cisco CWE-732
6.7
2019-05-03 CVE-2019-1724 Improper Authentication vulnerability in Cisco products
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
low complexity
cisco CWE-287
8.8
2019-05-03 CVE-2019-1715 Insufficient Entropy in PRNG vulnerability in Cisco products
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device.
network
low complexity
cisco CWE-332
7.5