Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-08-17 CVE-2017-6774 Files or Directories Accessible to External Parties vulnerability in Cisco ASR 5000 Software 21.0.V0.65839
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files.
network
low complexity
cisco CWE-552
4.0
2017-08-17 CVE-2017-6773 Improper Input Validation vulnerability in Cisco ASR 5000 Software 21.0.V0.65839
A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, local attacker to bypass the CLI restrictions and execute commands on the underlying operating system.
local
low complexity
cisco CWE-20
4.6
2017-08-17 CVE-2017-6772 Information Exposure vulnerability in Cisco Elastic Services Controller 2.3(2)
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information.
network
low complexity
cisco CWE-200
4.0
2017-08-17 CVE-2017-6771 Information Exposure vulnerability in Cisco Ultra Services Framework 21.0.V0.65839
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information.
network
low complexity
cisco CWE-200
5.0
2017-08-17 CVE-2017-6768 Untrusted Search Path vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges.
local
low complexity
cisco CWE-426
7.2
2017-08-17 CVE-2017-6767 Improper Privilege Management vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned.
network
high complexity
cisco CWE-269
4.6
2017-08-17 CVE-2017-6710 OS Command Injection vulnerability in Cisco Virtual Network Function Element Manager
A vulnerability in the Cisco Virtual Network Function (VNF) Element Manager could allow an authenticated, remote attacker to elevate privileges and run commands in the context of the root user on the server.
network
low complexity
cisco CWE-78
8.5
2017-08-07 CVE-2017-6770 Improper Input Validation vulnerability in Cisco products
Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database.
network
high complexity
cisco CWE-20
4.2
2017-08-07 CVE-2017-6769 Cross-site Scripting vulnerability in Cisco Secure Access Control System 5.8(0.8)/5.8(1.5)
A vulnerability in the web-based management interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system.
network
cisco CWE-79
3.5
2017-08-07 CVE-2017-6766 Unspecified vulnerability in Cisco Firesight System Software
A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting and inspecting traffic on an affected system.
network
low complexity
cisco
5.0