Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-1750 7PK - Errors vulnerability in Cisco IOS XE
A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload.
low complexity
cisco CWE-388
6.1
2019-03-28 CVE-2019-1747 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
5.0
2019-03-28 CVE-2019-1746 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2019-03-28 CVE-2019-1742 Improper Access Control vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information.
network
low complexity
cisco CWE-284
5.0
2019-03-22 CVE-2019-1765 Path Traversal vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem.
network
low complexity
cisco CWE-22
4.0
2019-03-22 CVE-2019-1764 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack.
network
cisco CWE-352
6.8
2019-03-22 CVE-2019-1763 Improper Access Control vulnerability in Cisco products
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-284
5.0
2019-03-11 CVE-2019-1702 Cross-site Scripting vulnerability in Cisco Enterprise Chat and Email 11.6(1)
Multiple vulnerabilities in the web-based management interface of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software.
network
cisco CWE-79
4.3
2019-03-11 CVE-2019-1617 Improper Control of Dynamically-Managed Code Resources vulnerability in Cisco Nx-Os
A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
low complexity
cisco CWE-913
6.1
2019-03-11 CVE-2019-1616 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
5.0