Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-02 CVE-2017-12281 Improper Authentication vulnerability in Cisco products
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass authentication and connect to an affected device.
5.4
2017-11-02 CVE-2017-12278 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition.
5.2
2017-11-02 CVE-2017-12276 SQL Injection vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection.
network
low complexity
cisco CWE-89
5.5
2017-11-02 CVE-2017-12275 Improper Input Validation vulnerability in Cisco Wireless LAN Controller Software
A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2017-11-02 CVE-2017-12274 Improper Input Validation vulnerability in Cisco products
A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (AP) to reload, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2017-11-02 CVE-2017-12273 Improper Input Validation vulnerability in Cisco products
A vulnerability in 802.11 association request frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (AP) to reload, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.1
2017-11-02 CVE-2017-12262 Improper Initialization vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the internal network of the device.
low complexity
cisco CWE-665
5.8
2017-10-24 CVE-2014-0691 Insufficient Entropy vulnerability in Cisco Webex Meetings Server 1.0
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.
network
low complexity
cisco CWE-331
5.0
2017-10-23 CVE-2017-15805 Path Traversal vulnerability in Cisco products
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.
network
low complexity
cisco CWE-22
5.0
2017-10-22 CVE-2017-12317 Use of Hard-coded Credentials vulnerability in Cisco Advanced Malware Protection
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software.
local
low complexity
cisco CWE-798
4.6