Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-12266 Uncontrolled Search Path Element vulnerability in Cisco Meeting APP
A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App.
local
low complexity
cisco CWE-427
4.2
2017-10-05 CVE-2017-12265 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka HREF XSS.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12264 Improper Input Validation vulnerability in Cisco Meeting Server
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2017-10-05 CVE-2017-12258 Cross-site Scripting vulnerability in Cisco Unified Communications Manager
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12257 Cross-site Scripting vulnerability in Cisco Webex Meetings Server
A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12256 Unspecified vulnerability in Cisco Wide Area Application Services
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device.
network
low complexity
cisco
6.5
2017-09-29 CVE-2017-12239 Use of Hard-coded Credentials vulnerability in Cisco IOS XE
A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system.
low complexity
cisco CWE-798
6.8
2017-09-29 CVE-2017-12238 Unspecified vulnerability in Cisco IOS
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition.
low complexity
cisco
6.5
2017-09-29 CVE-2017-12232 Unspecified vulnerability in Cisco IOS
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
low complexity
cisco
6.5
2017-09-29 CVE-2017-12228 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate.
network
high complexity
cisco CWE-295
5.9