Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2016-07-07 CVE-2016-1443 7PK - Security Features vulnerability in Cisco AMP Threat Grid Appliance
The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sample.
network
high complexity
cisco CWE-254
8.1
2016-07-07 CVE-2016-1442 Improper Input Validation vulnerability in Cisco Prime Infrastructure 3.0/3.1
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
network
low complexity
cisco CWE-20
8.8
2016-07-03 CVE-2016-1337 Information Exposure vulnerability in Cisco Epc3928 Firmware
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178.
network
high complexity
cisco CWE-200
8.1
2016-07-03 CVE-2016-1336 Improper Input Validation vulnerability in Cisco Epc3928 Firmware
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka Bug ID CSCuy28100.
network
low complexity
cisco CWE-20
7.5
2016-07-03 CVE-2016-1328 Improper Input Validation vulnerability in Cisco Epc3928 Firmware
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug ID CSCux24948.
network
low complexity
cisco CWE-20
7.5
2016-07-03 CVE-2016-1441 Improper Input Validation vulnerability in Cisco Cloud Network Automation Provisioner 1.0(0)
Cisco Cloud Network Automation Provisioner (CNAP) 1.0(0) in Cisco Configuration Assistant (CCA) allows remote attackers to bypass intended filesystem and administrative-endpoint restrictions via GET API calls, aka Bug ID CSCuy77145.
network
low complexity
cisco CWE-20
8.2
2016-07-03 CVE-2016-1394 Permissions, Privileges, and Access Controls vulnerability in Cisco Firesight System Software
Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238.
network
low complexity
cisco CWE-264
8.6
2016-07-02 CVE-2016-1408 Improper Input Validation vulnerability in Cisco products
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
network
low complexity
cisco CWE-20
8.8
2016-06-23 CVE-2016-1438 7PK - Security Features vulnerability in Cisco Asyncos 9.7.0125
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
network
low complexity
cisco CWE-254
7.5
2016-06-23 CVE-2016-1436 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco ASR 5000 Software
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1 packet, aka Bug ID CSCuz46198.
network
low complexity
cisco CWE-119
7.5