Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-05-18 CVE-2017-6652 Improper Input Validation vulnerability in Cisco Telepresence Ix5000 8.2.0Base
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device.
network
low complexity
cisco CWE-20
5.0
2017-05-18 CVE-2017-6621 Information Exposure vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data.
network
low complexity
cisco CWE-200
5.0
2017-05-16 CVE-2017-6658 Out-of-bounds Read vulnerability in Cisco Sourcefire Snort 3.0
Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array.
network
low complexity
cisco CWE-125
5.0
2017-05-16 CVE-2017-6657 Unspecified vulnerability in Cisco Snort++
Cisco Sourcefire Snort 3.0 before build 233 mishandles Ether Type Validation.
network
low complexity
cisco
5.0
2017-05-16 CVE-2017-6651 Information Exposure vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings.
network
low complexity
cisco CWE-200
5.0
2017-05-16 CVE-2017-3825 Improper Input Validation vulnerability in Cisco Telepresence CE and Telepresence TC
A vulnerability in the ICMP ingress packet processing of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause the TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.0
2017-05-03 CVE-2017-6629 Path Traversal vulnerability in Cisco Unity Connection 10.5(2)
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device.
network
low complexity
cisco CWE-22
5.0
2017-05-03 CVE-2017-6628 Improper Handling of Exceptional Conditions vulnerability in Cisco Wide Area Application Services 6.2.1/6.2.1A/6.2.3A
A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, and 6.2.3a could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition where the WAN optimization could stop functioning while the process restarts.
network
cisco CWE-755
4.3
2017-05-03 CVE-2017-6626 Information Exposure vulnerability in Cisco Unified Contact Center Enterprise 11.5(1)/11.6(1)
A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop.
network
low complexity
cisco CWE-200
5.0
2017-05-03 CVE-2017-6625 Unspecified vulnerability in Cisco Firepower Threat Defense
A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerability in the access control policy of Cisco Firepower System Software could allow an authenticated, remote attacker to cause an affected system to stop inspecting and processing packets, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
5.5