Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-21 CVE-2018-0362 Improper Authentication vulnerability in Cisco products
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user.
local
low complexity
cisco CWE-287
4.6
2018-06-21 CVE-2018-0358 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-770
5.0
2018-06-21 CVE-2018-0331 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Cisco Discovery Protocol (formerly known as CDP) subsystem of devices running, or based on, Cisco NX-OS Software contain a vulnerability that could allow an unauthenticated, adjacent attacker to create a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2018-06-21 CVE-2018-0309 Resource Exhaustion vulnerability in Cisco Nx-Os 7.0(3)I5(2)/7.0(3)I6(1)
A vulnerability in the implementation of a specific CLI command and the associated Simple Network Management Protocol (SNMP) MIB for Cisco NX-OS (in standalone NX-OS mode) on Cisco Nexus 3000 and 9000 Series Switches could allow an authenticated, remote attacker to exhaust system memory on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
6.8
2018-06-21 CVE-2018-0305 NULL Pointer Dereference vulnerability in Cisco products
A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.
network
low complexity
cisco CWE-476
5.0
2018-06-21 CVE-2018-0299 Improper Input Validation vulnerability in Cisco Nx-Os 4.1(2)E1(1R)
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco NX-OS on the Cisco Nexus 4000 Series Switch could allow an authenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
6.8
2018-06-20 CVE-2018-0330 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands with elevated privileges.
network
low complexity
cisco CWE-78
6.5
2018-06-20 CVE-2018-0294 Unspecified vulnerability in Cisco Firepower Extensible Operating System, Fxos and Nx-Os
A vulnerability in the write-erase feature of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to configure an unauthorized administrator account for an affected device.
local
low complexity
cisco
6.7
2018-06-20 CVE-2018-0291 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly.
network
low complexity
cisco CWE-20
6.8
2018-06-07 CVE-2018-0357 Cross-site Scripting vulnerability in Cisco Webex Meetings 1.3.5
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system.
network
cisco CWE-79
4.3