Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2015-07-10 CVE-2015-4236 Resource Management Errors vulnerability in Cisco products
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.
network
cisco CWE-399
4.3
2015-07-10 CVE-2015-4254 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence Advanced Media Gateway 1.1(1.40)
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Advanced Media Gateway devices with software 1.1(1.40) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90732.
network
cisco CWE-352
6.8
2015-07-10 CVE-2015-4259 Cryptographic Issues vulnerability in Cisco Unified Computing System 1.5(3)/1.6(0.16)
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.
network
cisco CWE-310
4.3
2015-07-10 CVE-2015-4260 Cross-site Scripting vulnerability in Cisco Hosted Collaboration Solution 10.6(1)Base
Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.
network
cisco CWE-79
4.3
2015-07-10 CVE-2015-4244 OS Command Injection vulnerability in Cisco ASR 5000 Series Software 14.0
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
local
low complexity
cisco CWE-78
7.2
2015-07-10 CVE-2015-4258 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence MSE 8000 Series
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.
network
cisco CWE-352
6.8
2015-07-10 CVE-2015-4257 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence MCU Software 4.5(1.55)
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.
network
cisco CWE-352
6.8
2015-07-10 CVE-2015-4256 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence IP VCR 3.0 1.27
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.
network
cisco CWE-352
6.8
2015-07-10 CVE-2015-4255 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence IP Gateway 2.0.3.34
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.
network
cisco CWE-352
6.8
2015-07-10 CVE-2015-4253 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Telepresence Serial Gateway 1.0.1.42
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Serial Gateway devices with software 1.0(1.42) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90728.
network
cisco CWE-352
6.8