Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-11 CVE-2019-1615 Improper Verification of Cryptographic Signature vulnerability in Cisco Nx-Os
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device.
local
low complexity
cisco CWE-347
4.6
2019-03-11 CVE-2019-1613 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
4.6
2019-03-08 CVE-2019-1603 Improper Authorization vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level privileges to the administrator level.
local
low complexity
cisco CWE-285
4.6
2019-03-07 CVE-2019-1600 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is stored in the file system of an affected system.
local
low complexity
cisco CWE-732
4.4
2019-03-06 CVE-2019-1595 Improper Control of Dynamically-Managed Code Resources vulnerability in Cisco Nx-Os
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-913
6.1
2019-03-06 CVE-2019-1594 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.1
2019-02-21 CVE-2019-1700 Resource Management Errors vulnerability in Cisco Firepower 9000 Firmware 2.2(200.8)
A vulnerability in field-programmable gate array (FPGA) ingress buffer management for the Cisco Firepower 9000 Series with the Cisco Firepower 2-port 100G double-width network module (PID: FPR9K-DNM-2X100G) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
5.7
2019-02-21 CVE-2019-1698 XXE vulnerability in Cisco IOT Field Network Director
A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
4.0
2019-02-21 CVE-2019-1691 Improper Handling of Exceptional Conditions vulnerability in Cisco Firepower Threat Defense
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
5.0
2019-02-21 CVE-2019-1685 Cross-site Scripting vulnerability in Cisco Unity Connection 12.5
A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
network
low complexity
cisco CWE-79
6.1