Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2018-02-22 CVE-2018-0146 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Data Center Analytics Framework 3.1
A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
5.4
2018-02-22 CVE-2018-0145 Cross-site Scripting vulnerability in Cisco Data Center Analytics Framework 3.1
A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2018-02-22 CVE-2018-0139 Unspecified vulnerability in Cisco Unified Customer Voice Portal 11.5(1)/11.6
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition.
network
low complexity
cisco
8.6
2018-02-22 CVE-2018-0130 Insecure Default Initialization of Resource vulnerability in Cisco Virtual Managed Services 3.0
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system.
network
low complexity
cisco CWE-1188
critical
9.8
2018-02-22 CVE-2018-0124 Key Management Errors vulnerability in Cisco Unified Communications Domain Manager
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code.
network
low complexity
cisco CWE-320
critical
9.8
2018-02-22 CVE-2018-0121 Improper Authentication vulnerability in Cisco products
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system.
network
low complexity
cisco CWE-287
critical
9.8
2018-02-08 CVE-2018-0140 Forced Browsing vulnerability in Cisco products
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information.
network
low complexity
cisco CWE-425
6.5
2018-02-08 CVE-2018-0138 Protection Mechanism Failure vulnerability in Cisco Firepower Threat Defense
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol.
network
low complexity
cisco CWE-693
5.3
2018-02-08 CVE-2018-0137 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Prime Network 4.3(0.0)Pp6/4.3(2.0)Pp1
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-770
8.6
2018-02-08 CVE-2018-0135 Improper Input Validation vulnerability in Cisco Unified Communications Manager 11.0(1.24075.1)
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system.
network
low complexity
cisco CWE-20
4.3