Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-01-26 CVE-2017-3800 Improper Input Validation vulnerability in Cisco Email Security Appliance 9.7.1066/9.7.1Hp2207/9.8.5085
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device.
network
low complexity
cisco CWE-20
5.8
2017-01-26 CVE-2017-3799 Open Redirect vulnerability in Cisco Webex Meeting Center Wbs28Base
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection.
network
low complexity
cisco CWE-601
5.4
2017-01-26 CVE-2017-3798 Cross-site Scripting vulnerability in Cisco Unified Communications Manager 11.5(1.12000.1)
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-01-26 CVE-2017-3797 Information Exposure vulnerability in Cisco Webex Meetings Server 2.7.1/2.7Base
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco WebEx administration server.
network
low complexity
cisco CWE-200
5.3
2017-01-26 CVE-2017-3796 OS Command Injection vulnerability in Cisco Webex Meetings Server 2.6.0
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts.
network
low complexity
cisco CWE-78
7.2
2017-01-26 CVE-2017-3795 Improper Authentication vulnerability in Cisco Webex Meetings Server 2.6.0
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user.
network
low complexity
cisco CWE-287
5.4
2017-01-26 CVE-2017-3794 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Webex Meetings Server 2.6.0
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user.
network
low complexity
cisco CWE-352
8.8
2017-01-26 CVE-2016-9222 Cross-site Scripting vulnerability in Cisco Netflow Generation Appliance 1.0(2)
A vulnerability in the web-based management interface of Cisco NetFlow Generation Appliance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2017-01-26 CVE-2016-9221 Resource Management Errors vulnerability in Cisco Aironet Access Point Software 8.2(121.12)/8.4(1.82)
A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause authentication to fail.
low complexity
cisco CWE-399
4.3
2017-01-26 CVE-2016-9220 Resource Management Errors vulnerability in Cisco Aironet Access Point Software 8.2(130.0)
A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the connection table to be full of invalid connections and be unable to process new incoming requests.
low complexity
cisco CWE-399
4.3