Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-06-08 CVE-2017-6639 Missing Authorization vulnerability in Cisco Prime Data Center Network Manager 10.1.0/10.1(1)/10.1(2)
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system.
network
low complexity
cisco CWE-862
critical
9.8
2017-06-08 CVE-2017-6638 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYSTEM account.
local
low complexity
cisco CWE-20
7.8
2017-05-22 CVE-2017-6654 Cross-site Scripting vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5)/11.0(1.10000.10)/11.5(1.10000.6)
A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 through 11.5 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-05-22 CVE-2017-6653 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Identity Services Engine 2.1(0.474)
A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to respond to new or established connection requests.
network
low complexity
cisco CWE-770
7.5
2017-05-22 CVE-2017-6650 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-77
7.8
2017-05-22 CVE-2017-6649 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-77
7.8
2017-05-22 CVE-2017-6647 Information Exposure vulnerability in Cisco Remote Expert Manager 11.0.0
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Temporary File information on an affected system.
network
low complexity
cisco CWE-200
5.3
2017-05-22 CVE-2017-6646 Information Exposure vulnerability in Cisco Remote Expert Manager 11.0.0
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system.
network
low complexity
cisco CWE-200
5.3
2017-05-22 CVE-2017-6645 Information Exposure vulnerability in Cisco Remote Expert Manager 11.0.0
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Temporary Directory information on an affected system.
network
low complexity
cisco CWE-200
5.3
2017-05-22 CVE-2017-6644 Information Exposure vulnerability in Cisco Remote Expert Manager 11.0.0
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system.
network
low complexity
cisco CWE-200
5.3