Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-15370 Unspecified vulnerability in Cisco IOS ROM Monitor 15.1(2)Sy3
A vulnerability in Cisco IOS ROM Monitor (ROMMON) Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, local attacker to bypass Cisco Secure Boot validation checks and load a compromised software image on an affected device.
low complexity
cisco
6.8
2018-10-05 CVE-2018-15369 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
high complexity
cisco CWE-20
6.8
2018-10-05 CVE-2018-15368 OS Command Injection vulnerability in Cisco IOS XE 15.4(3)S
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0481 OS Command Injection vulnerability in Cisco IOS XE 15.3(3)S3.16/16.7.1/16.7(1)
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0480 Race Condition vulnerability in Cisco IOS XE 3.6(5)
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition.
high complexity
cisco CWE-362
6.1
2018-10-05 CVE-2018-0477 OS Command Injection vulnerability in Cisco IOS XE 15.3(3)S3.16/16.7.1/16.7(1)
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0476 Unspecified vulnerability in Cisco IOS XE 15.5(3)S5.1/15.5(3)S6.1/16.6.2
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
high complexity
cisco
5.9
2018-10-05 CVE-2018-0469 Double Free vulnerability in Cisco IOS XE 16.5.1
A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
high complexity
cisco CWE-415
6.8
2018-10-05 CVE-2018-0466 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload.
low complexity
cisco
6.5
2018-10-05 CVE-2018-0465 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected system.
network
low complexity
cisco CWE-79
6.1