Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-01-10 CVE-2018-15461 Cross-site Scripting vulnerability in Cisco Webex Business Suite
A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack.
network
low complexity
cisco CWE-79
6.1
2019-01-10 CVE-2018-15457 Cross-site Scripting vulnerability in Cisco Prime Infrastructure 3.5
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2019-01-10 CVE-2018-15456 Insufficiently Protected Credentials vulnerability in Cisco Identity Services Engine
A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text.
network
low complexity
cisco CWE-522
4.9
2019-01-10 CVE-2018-0484 Unspecified vulnerability in Cisco IOS 16.6.2/16.6.4
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration.
network
low complexity
cisco
6.5
2019-01-10 CVE-2018-0483 Cross-site Scripting vulnerability in Cisco Jabber 10.0(0)
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system.
network
low complexity
cisco CWE-79
5.4
2019-01-10 CVE-2018-0482 Cross-site Scripting vulnerability in Cisco Prime Infrastructure 3.5(0.0)
A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system.
network
low complexity
cisco CWE-79
5.4
2019-01-10 CVE-2018-0449 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Jabber 12.1(0)
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated privileges.
local
low complexity
cisco CWE-732
4.2
2019-01-10 CVE-2018-0282 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
high complexity
cisco
6.8
2018-11-13 CVE-2018-15452 Uncontrolled Search Path Element vulnerability in Cisco Advanced Malware Protection for Endpoints
A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could allow an authenticated, local attacker to disable system scanning services or take other actions to prevent detection of unauthorized intrusions.
local
low complexity
cisco CWE-427
6.7
2018-11-08 CVE-2018-15451 Cross-site Scripting vulnerability in Cisco Prime Service Catalog 12.1
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
5.4