Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-01-23 CVE-2018-0187 Information Exposure vulnerability in Cisco Identity Services Engine 2.4(0.901.1)/2.4(0.901)
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts.
network
low complexity
cisco CWE-200
6.5
2019-01-15 CVE-2018-15463 Cross-site Scripting vulnerability in Cisco Identity Services Engine Software 2.4(0.357)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface.
network
low complexity
cisco CWE-79
6.1
2019-01-15 CVE-2018-15440 Cross-site Scripting vulnerability in Cisco Identity Services Engine Software 2.4(0.357)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2019-01-11 CVE-2018-15467 Cross-site Scripting vulnerability in Cisco Telepresence Management Suite 15.7
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2019-01-11 CVE-2018-15466 Missing Authentication for Critical Function vulnerability in Cisco Policy Suite for Mobile 12.0.0
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface.
network
high complexity
cisco CWE-306
3.7
2019-01-11 CVE-2018-15464 Resource Exhaustion vulnerability in Cisco ASR 900 Series Software 16.6.2
A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
5.8
2019-01-10 CVE-2018-15461 Cross-site Scripting vulnerability in Cisco Webex Business Suite
A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
network
low complexity
cisco CWE-79
6.1
2019-01-10 CVE-2018-15460 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Asyncos
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-770
8.6
2019-01-10 CVE-2018-15458 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Secure Firewall Management Center 6.2.2/6.2.3/6.3.0
A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction with remote authentication, could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-770
7.5
2019-01-10 CVE-2018-15457 Cross-site Scripting vulnerability in Cisco Prime Infrastructure 3.5
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system.
network
low complexity
cisco CWE-79
6.1