Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2018-04-19 CVE-2018-0238 Improper Authentication vulnerability in Cisco Unified Computing System Director 6.5(0.0)/6.5(0.1)
A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on any virtual machine.
network
low complexity
cisco CWE-287
critical
9.9
2018-04-19 CVE-2018-0237 Use of Incorrectly-Resolved Name or Reference vulnerability in Cisco Advanced Malware Protection for Endpoints 1.4(5)
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection.
network
low complexity
cisco CWE-706
5.8
2018-04-19 CVE-2018-0233 Resource Exhaustion vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the Secure Sockets Layer (SSL) packet reassembly functionality of the detection engine in Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause the detection engine to consume excessive system memory on an affected device, which could cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6
2018-04-19 CVE-2018-0231 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
8.6
2018-04-19 CVE-2018-0230 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the internal packet-processing functionality of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6
2018-04-19 CVE-2018-0229 Session Fixation vulnerability in Cisco products
A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-On (SSO) authentication for Cisco AnyConnect Secure Mobility Client for Desktop Platforms, Cisco Adaptive Security Appliance (ASA) Software, and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish an authenticated AnyConnect session through an affected device running ASA or FTD Software.
network
low complexity
cisco CWE-384
6.5
2018-04-19 CVE-2018-0228 Improper Locking vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-667
8.6
2018-04-19 CVE-2018-0227 Improper Certificate Validation vulnerability in Cisco products
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps.
network
low complexity
cisco CWE-295
7.5
2018-04-19 CVE-2018-0112 Improper Input Validation vulnerability in Cisco products
A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system.
network
low complexity
cisco CWE-20
critical
9.0
2018-04-02 CVE-2018-0194 OS Command Injection vulnerability in Cisco IOS XE
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device.
local
low complexity
cisco CWE-78
7.8