Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2018-0382 Improper Authentication vulnerability in Cisco Wireless LAN Controller Software 8.1(111.0)/8.5(120.0)
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
low complexity
cisco CWE-287
7.5
2019-04-17 CVE-2018-0248 Improper Input Validation vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is using this GUI, causing a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
4.9
2019-04-17 CVE-2018-7340 Improper Verification of Cryptographic Signature vulnerability in Cisco DUO Network Gateway
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
network
low complexity
cisco CWE-347
7.5
2019-04-04 CVE-2019-1828 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials.
network
high complexity
cisco CWE-327
8.1
2019-04-04 CVE-2019-1827 Cross-site Scripting vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the service.
network
low complexity
cisco CWE-79
6.1
2019-03-28 CVE-2019-1762 Information Exposure vulnerability in Cisco IOS and IOS XE
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device.
local
low complexity
cisco CWE-200
4.4
2019-03-28 CVE-2019-1761 Improper Initialization vulnerability in Cisco IOS and IOS XE
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device.
low complexity
cisco CWE-665
4.3
2019-03-28 CVE-2019-1760 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload.
network
high complexity
cisco CWE-20
5.9
2019-03-28 CVE-2019-1759 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface.
network
low complexity
cisco CWE-287
5.3
2019-03-28 CVE-2019-1758 Improper Authentication vulnerability in Cisco IOS
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication.
low complexity
cisco CWE-287
4.3