Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-02 CVE-2019-12630 Deserialization of Untrusted Data vulnerability in Cisco Security Manager
A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
network
low complexity
cisco CWE-502
7.5
2019-09-25 CVE-2019-12717 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges.
local
low complexity
cisco CWE-78
7.2
2019-09-25 CVE-2019-12709 OS Command Injection vulnerability in Cisco IOS XR
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges.
local
low complexity
cisco CWE-78
7.2
2019-09-25 CVE-2019-12672 Link Following vulnerability in Cisco IOS 16.9.1
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-59
7.2
2019-09-25 CVE-2019-12671 Incorrect Authorization vulnerability in Cisco IOS XE 16.11.1
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS).
local
low complexity
cisco CWE-863
7.8
2019-09-25 CVE-2019-12669 Improper Input Validation vulnerability in Cisco IOS 15.2(3)E/15.2(3)E5/16.11.1
A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.8
2019-09-25 CVE-2019-12666 Path Traversal vulnerability in Cisco IOS XE
A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software.
local
low complexity
cisco CWE-22
7.2
2019-09-25 CVE-2019-12664 Improper Authentication vulnerability in Cisco IOS XE 16.6.4
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication.
network
low complexity
cisco CWE-287
7.5
2019-09-25 CVE-2019-12663 Improper Input Validation vulnerability in Cisco IOS XE 16.12.1/16.6.4
A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.8
2019-09-25 CVE-2019-12662 Improper Verification of Cryptographic Signature vulnerability in Cisco products
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device.
local
low complexity
cisco CWE-347
7.2