Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-05 CVE-2019-1868 Unspecified vulnerability in Cisco Webex Meetings Server 2.6
A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information.
network
low complexity
cisco
5.0
2019-06-05 CVE-2019-1845 Improper Input Validation vulnerability in Cisco products
A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to authenticate, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.0
2019-06-05 CVE-2019-1842 Improper Authentication vulnerability in Cisco IOS XR Firmware
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames.
network
low complexity
cisco CWE-287
5.5
2019-05-16 CVE-2019-1780 Argument Injection or Modification vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileges.
local
low complexity
cisco CWE-88
6.7
2019-05-16 CVE-2019-1860 Resource Injection vulnerability in Cisco Unified Intelligence Center 12.0(1)
A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center.
network
high complexity
cisco CWE-99
4.0
2019-05-16 CVE-2019-1853 Out-of-bounds Read vulnerability in Cisco Anyconnect Secure Mobility Client 4.6(2074)
A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system.
network
low complexity
cisco CWE-125
5.0
2019-05-16 CVE-2019-1851 Unspecified vulnerability in Cisco Identity Services Engine 2.2(0.470)/2.3(0.298)/2.4(0.357)
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE.
network
low complexity
cisco
4.0
2019-05-16 CVE-2019-1849 Improper Check for Unusual or Exceptional Conditions vulnerability in Cisco IOS XR
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-754
6.1
2019-05-16 CVE-2019-1846 Improper Input Validation vulnerability in Cisco IOS XR 5.3.3
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2019-05-16 CVE-2019-1833 Protection Mechanism Failure vulnerability in Cisco Firepower Management Center
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies.
network
low complexity
cisco CWE-693
5.0