Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-06 CVE-2018-5390 Resource Exhaustion vulnerability in multiple products
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
7.5
2018-08-01 CVE-2018-0413 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Identity Services Engine Software
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8
2018-07-18 CVE-2018-0402 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
network
low complexity
cisco CWE-352
8.8
2018-07-18 CVE-2018-0394 Improper Input Validation vulnerability in Cisco Cloud Services Platform 2100 2.2(4)
A vulnerability in the web upload function of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to obtain restricted shell access on an affected system.
network
low complexity
cisco CWE-20
8.8
2018-07-18 CVE-2018-0387 Improper Input Validation vulnerability in Cisco Webex Teams
A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute arbitrary code on the user's device, possibly with elevated privileges.
network
low complexity
cisco CWE-20
8.8
2018-07-18 CVE-2018-0379 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files.
local
low complexity
cisco CWE-119
7.8
2018-07-18 CVE-2018-0372 Resource Exhaustion vulnerability in Cisco Nx-Os 13.0(1K)
A vulnerability in the DHCPv6 feature of the Cisco Nexus 9000 Series Fabric Switches in Application-Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause the device to run low on system memory, which could result in a Denial of Service (DoS) condition on an affected system.
network
low complexity
cisco CWE-400
7.5
2018-07-18 CVE-2018-0351 Command Injection vulnerability in Cisco products
A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-77
7.8
2018-07-18 CVE-2018-0350 Command Injection vulnerability in Cisco products
A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.
network
low complexity
cisco CWE-77
8.8
2018-07-18 CVE-2018-0348 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.
network
low complexity
cisco CWE-78
7.2