Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-6720 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
6.5
2017-09-21 CVE-2017-12255 Improper Input Validation vulnerability in Cisco Unified Computing System 1.5(1C)
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access.
local
low complexity
cisco CWE-20
6.7
2017-09-21 CVE-2017-12254 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack.
network
low complexity
cisco CWE-79
6.1
2017-09-21 CVE-2017-12253 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions.
network
low complexity
cisco CWE-352
8.8
2017-09-21 CVE-2017-12252 Untrusted Search Path vulnerability in Cisco Findit Network Discovery Utility 2.0.3
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availability, confidentiality, and integrity.
local
low complexity
cisco CWE-426
7.8
2017-09-21 CVE-2017-12250 Improper Input Validation vulnerability in Cisco Wide Area Application Services 6.2(3A)
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2017-09-21 CVE-2017-12248 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-09-21 CVE-2017-12219 Unspecified vulnerability in Cisco products
A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2017-09-21 CVE-2017-12215 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages.
local
low complexity
cisco CWE-20
7.1
2017-09-21 CVE-2017-12214 Improper Input Validation vulnerability in Cisco Unified Customer Voice Portal 10.5/11.0/11.5
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.
network
low complexity
cisco CWE-20
8.8