Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0189 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, network attacker to cause a denial of service (DoS) condition.
network
high complexity
cisco
5.3
2018-03-28 CVE-2018-0188 Cross-site Scripting vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software.
network
low complexity
cisco CWE-79
6.1
2018-03-28 CVE-2018-0186 Cross-site Scripting vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software.
network
low complexity
cisco CWE-79
6.1
2018-03-28 CVE-2018-0184 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device.
local
low complexity
cisco CWE-78
6.7
2018-03-28 CVE-2018-0183 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device.
local
low complexity
cisco CWE-78
6.7
2018-03-28 CVE-2018-0180 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
network
high complexity
cisco
5.9
2018-03-28 CVE-2018-0179 Unspecified vulnerability in Cisco IOS
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
network
high complexity
cisco
5.9
2018-03-28 CVE-2018-0163 Improper Authentication vulnerability in Cisco IOS
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port.
low complexity
cisco CWE-287
6.5
2018-03-28 CVE-2018-0161 Unspecified vulnerability in Cisco IOS 15.2(5)E
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability.
network
high complexity
cisco
6.3
2018-03-28 CVE-2018-0160 Double Free vulnerability in Cisco IOS XE 15.5(3)S
A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
network
high complexity
cisco CWE-415
6.3