Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2017-6682 OS Command Injection vulnerability in Cisco Elastic Services Controller 2.2(9.76)
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system.
network
low complexity
cisco CWE-78
8.8
2017-06-13 CVE-2017-6681 Information Exposure vulnerability in Cisco Ultra Services Framework 21.0.0
A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a relative path traversal attack, enabling an attacker to read sensitive files on the system.
network
low complexity
cisco CWE-200
7.5
2017-06-13 CVE-2017-6680 Improper Input Validation vulnerability in Cisco Ultra Services Framework 21.0.0
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6675 Cross-site Scripting vulnerability in Cisco Industrial Network Director 1.1(0.176)
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system.
network
low complexity
cisco CWE-79
6.1
2017-06-13 CVE-2017-6674 Improper Input Validation vulnerability in Cisco Firesight System
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6673 Information Exposure vulnerability in Cisco Secure Firewall Management Center 6.1.0.2/6.2.0
A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information.
network
low complexity
cisco CWE-200
6.5
2017-06-13 CVE-2017-6671 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware 10.0.1087/9.7.1066
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6670 Open Redirect vulnerability in Cisco Unified Communications Domain Manager 8.1(7)Er1
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue.
network
low complexity
cisco CWE-601
6.1
2017-06-13 CVE-2017-6668 SQL Injection vulnerability in Cisco Unified Communications Domain Manager 8.1(7)Er1
Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection.
network
low complexity
cisco CWE-89
4.9
2017-06-13 CVE-2017-6667 Improper Input Validation vulnerability in Cisco Context Service Development KIT 2.0
A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server.
network
low complexity
cisco CWE-20
critical
9.8