Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0157 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload.
network
low complexity
cisco
8.6
2018-03-28 CVE-2018-0156 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2018-03-28 CVE-2018-0155 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS and IOS XE
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
8.6
2018-03-28 CVE-2018-0154 Unspecified vulnerability in Cisco IOS
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2018-03-28 CVE-2018-0152 Insufficient Session Expiration vulnerability in Cisco IOS XE 16.1.1
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device.
network
low complexity
cisco CWE-613
8.8
2018-03-28 CVE-2018-0151 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE 16.5.1
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
network
low complexity
cisco CWE-119
critical
9.8
2018-03-28 CVE-2018-0150 Use of Hard-coded Credentials vulnerability in Cisco IOS XE 16.5.1
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability.
network
low complexity
cisco CWE-798
critical
9.8
2018-03-27 CVE-2018-0198 Forced Browsing vulnerability in Cisco Unified Communications Manager
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data.
network
low complexity
cisco CWE-425
5.3
2018-03-27 CVE-2017-12319 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
network
high complexity
cisco
5.9
2018-03-27 CVE-2017-12310 Cleartext Transmission of Sensitive Information vulnerability in Cisco Spark Hybrid Calendar Service
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request.
network
low complexity
cisco CWE-319
7.5