Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2015-03-28 CVE-2015-0679 Improper Input Validation vulnerability in Cisco Wireless LAN Controller Software 7.3(103.8)/7.4(110.0)
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980.
low complexity
cisco CWE-20
6.1
2015-03-28 CVE-2015-0658 Improper Input Validation vulnerability in Cisco Nx-Os
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
7.9
2015-03-26 CVE-2015-0673 Information Exposure vulnerability in Cisco Mobility Services Engine 8.0(110.0)
Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.
network
low complexity
cisco CWE-200
4.0
2015-03-26 CVE-2015-0672 Resource Management Errors vulnerability in Cisco IOS XR 5.2.2
The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
network
low complexity
cisco CWE-399
5.0
2015-03-26 CVE-2015-0650 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The Service Discovery Gateway (aka mDNS Gateway) in Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 3.9.xS and 3.10.xS before 3.10.4S, 3.11.xS before 3.11.3S, 3.12.xS before 3.12.2S, and 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) by sending malformed mDNS UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCup70579.
network
low complexity
cisco CWE-20
7.8
2015-03-26 CVE-2015-0649 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
network
low complexity
cisco CWE-20
7.8
2015-03-26 CVE-2015-0648 Resource Management Errors vulnerability in Cisco IOS
Memory leak in Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (memory consumption) via crafted Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun49658.
network
low complexity
cisco CWE-399
7.8
2015-03-26 CVE-2015-0647 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) UDP packets, aka Bug ID CSCum98371.
network
low complexity
cisco CWE-20
7.8
2015-03-26 CVE-2015-0646 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCum94811.
network
low complexity
cisco CWE-399
7.8
2015-03-26 CVE-2015-0645 Improper Input Validation vulnerability in Cisco IOS XE
The Layer 4 Redirect (L4R) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.2S, 3.13 before 3.13.1S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to cause a denial of service (device reload) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuq59131.
network
low complexity
cisco CWE-20
7.8