Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-06 CVE-2019-1921 Improper Input Validation vulnerability in Cisco Email Security Appliance 12.0.0419
A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device.
network
low complexity
cisco CWE-20
5.0
2019-07-06 CVE-2019-1911 Containment Errors (Container Errors) vulnerability in Cisco Hosted Collaboration Solution
A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell.
local
low complexity
cisco CWE-216
4.6
2019-07-06 CVE-2019-1909 Improper Input Validation vulnerability in Cisco IOS XR
A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.
network
cisco CWE-20
4.3
2019-07-06 CVE-2019-1892 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device.
network
low complexity
cisco CWE-119
5.0
2019-07-06 CVE-2019-1891 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
5.0
2019-07-06 CVE-2019-1887 Out-of-bounds Write vulnerability in Cisco Unified Communications Manager
A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
5.0
2019-07-04 CVE-2019-1886 Improper Certificate Validation vulnerability in Cisco Asyncos and web Security Appliance
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-295
5.0
2019-07-04 CVE-2019-1884 Improper Input Validation vulnerability in Cisco Asyncos and web Security Appliance
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
4.0
2019-06-27 CVE-2019-1622 Improper Access Control vulnerability in Cisco Data Center Network Manager 11.0(1)
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device.
network
low complexity
cisco CWE-284
5.0
2019-06-27 CVE-2019-1621 Permissions, Privileges, and Access Controls vulnerability in Cisco Data Center Network Manager 11.0(1)
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device.
network
low complexity
cisco CWE-264
5.0