Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-1840 Improper Initialization vulnerability in Cisco Prime Network Registrar
A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system.
network
low complexity
cisco CWE-665
7.5
2019-04-18 CVE-2019-1837 Improper Input Validation vulnerability in Cisco Unified Communications Manager
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI.
network
low complexity
cisco CWE-20
7.5
2019-04-18 CVE-2019-1797 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration.
network
low complexity
cisco CWE-352
8.8
2019-04-17 CVE-2019-1718 Unspecified vulnerability in Cisco Identity Services Engine 2.1(0.907)
A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2019-04-17 CVE-2019-1712 Improper Input Validation vulnerability in Cisco IOS XR
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2019-04-17 CVE-2019-1711 Improper Input Validation vulnerability in Cisco IOS XR
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2019-04-17 CVE-2019-1686 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device.
network
low complexity
cisco
8.6
2019-04-17 CVE-2019-1654 Missing Authentication for Critical Function vulnerability in Cisco Ap-Cos
A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication, which allows for root access to the underlying Linux OS.
local
low complexity
cisco CWE-306
7.8
2019-04-17 CVE-2018-0382 Improper Authentication vulnerability in Cisco Wireless LAN Controller Software 8.1(111.0)/8.5(120.0)
A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
low complexity
cisco CWE-287
7.5
2019-04-17 CVE-2018-7340 Improper Verification of Cryptographic Signature vulnerability in Cisco DUO Network Gateway
Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
network
low complexity
cisco CWE-347
7.5