Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-02-21 CVE-2019-1659 Improper Certificate Validation vulnerability in Cisco Prime Infrastructure
A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI.
network
cisco CWE-295
5.8
2019-02-08 CVE-2019-1676 Improper Input Validation vulnerability in Cisco Meeting Server
A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco Meeting Server.
network
low complexity
cisco CWE-20
5.0
2019-02-08 CVE-2019-1672 Resource Exhaustion vulnerability in Cisco web Security Appliance 10.1.0204/10.5.2072/11.5.1Fcs115
A vulnerability in the Decryption Policy Default Action functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured drop policy and allow traffic onto the network that should have been denied.
network
low complexity
cisco CWE-400
5.0
2019-02-07 CVE-2019-1671 Cross-site Scripting vulnerability in Cisco Firepower Management Center
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system.
network
cisco CWE-79
4.3
2019-02-07 CVE-2019-1670 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 9.5(1)
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
cisco CWE-79
4.3
2019-02-07 CVE-2019-1661 Cross-site Scripting vulnerability in Cisco Telepresence Management Suite 15.0
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
cisco CWE-79
4.3
2019-02-07 CVE-2019-1680 Improper Input Validation vulnerability in Cisco Webex Business Suite and Webex Meetings Online
A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser.
network
low complexity
cisco CWE-20
4.3
2019-02-07 CVE-2019-1679 Server-Side Request Forgery (SSRF) vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host.
network
low complexity
cisco CWE-918
5.0
2019-02-07 CVE-2019-1660 Permissions, Privileges, and Access Controls vulnerability in Cisco Telepresence Management Suite
A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device.
network
low complexity
cisco CWE-264
5.0
2019-02-07 CVE-2019-1678 Improper Input Validation vulnerability in Cisco Meeting Server 2.3.6
A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint.
network
low complexity
cisco CWE-20
4.3