Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-05-03 CVE-2019-1854 Path Traversal vulnerability in Cisco Telepresence Video Communication Server X8.11.4
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device.
network
low complexity
cisco CWE-22
4.0
2019-05-03 CVE-2019-1852 Cross-site Scripting vulnerability in Cisco Network Registrar 9.1(2)
A vulnerability in the web-based management interface of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
network
cisco CWE-79
4.3
2019-05-03 CVE-2019-1844 Improper Input Validation vulnerability in Cisco Email Security Appliance 11.1.0131
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device.
network
low complexity
cisco CWE-20
5.0
2019-05-03 CVE-2019-1836 Path Traversal vulnerability in Cisco Nx-Os 14.0(3D)
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to overwrite system files.
local
low complexity
cisco CWE-22
6.6
2019-05-03 CVE-2019-1807 Session Fixation vulnerability in Cisco Umbrella
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session.
network
cisco CWE-384
6.8
2019-05-03 CVE-2019-1724 Improper Authentication vulnerability in Cisco products
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system.
network
cisco CWE-287
6.8
2019-05-03 CVE-2019-1715 Insufficient Entropy in PRNG vulnerability in Cisco products
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device.
network
low complexity
cisco CWE-332
5.0
2019-05-03 CVE-2019-1705 Improper Resource Shutdown or Release vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services.
network
high complexity
cisco CWE-404
5.9
2019-05-03 CVE-2019-1704 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
Multiple vulnerabilities in the Server Message Block (SMB) Protocol preprocessor detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent or remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
5.0
2019-05-03 CVE-2019-1701 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance Software
Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device.
network
low complexity
cisco CWE-79
4.8