Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-1800 Improper Input Validation vulnerability in Cisco products
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2019-04-18 CVE-2019-1799 Improper Input Validation vulnerability in Cisco products
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2019-04-18 CVE-2019-1797 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on the device with the privileges of the user, including modifying the device configuration.
network
cisco CWE-352
6.8
2019-04-18 CVE-2019-1796 Improper Input Validation vulnerability in Cisco products
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2019-04-18 CVE-2019-1794 Uncontrolled Search Path Element vulnerability in Cisco Meeting Server 2.2
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing.
local
low complexity
cisco CWE-427
5.1
2019-04-18 CVE-2019-1792 Cross-site Scripting vulnerability in Cisco Umbrella
A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella.
network
low complexity
cisco CWE-79
6.1
2019-04-18 CVE-2019-1777 Cross-site Scripting vulnerability in Cisco Registered Envelope Service 5.3.4027
A vulnerability in the web-based interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the service.
network
low complexity
cisco CWE-79
5.4
2019-04-18 CVE-2019-1722 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
network
cisco CWE-352
4.3
2019-04-18 CVE-2019-1721 Resource Management Errors vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-399
6.8
2019-04-18 CVE-2019-1720 Improper Input Validation vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-20
6.8