Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2017-3820 Improper Initialization vulnerability in Cisco IOS XE 3.13.6S/3.16.2S/3.17.1S
A vulnerability in Simple Network Management Protocol (SNMP) functions of Cisco ASR 1000 Series Aggregation Services Routers running Cisco IOS XE Software Release 3.13.6S, 3.16.2S, or 3.17.1S could allow an authenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-665
6.8
2017-02-03 CVE-2017-3818 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware 9.7.1066
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device, aka a Malformed MIME Header Filtering Bypass.
network
low complexity
cisco CWE-20
5.0
2017-02-03 CVE-2017-3814 Improper Input Validation vulnerability in Cisco Firepower Management Center
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass.
network
low complexity
cisco CWE-20
5.0
2017-02-03 CVE-2017-3810 Open Redirect vulnerability in Cisco Prime Service Catalog 10.0(R2)Base
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system.
network
cisco CWE-601
4.9
2017-02-03 CVE-2017-3809 Improper Input Validation vulnerability in Cisco Firepower Management Center 6.1.0/6.2.0
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base.
network
low complexity
cisco CWE-20
5.0
2017-02-03 CVE-2017-3806 OS Command Injection vulnerability in Cisco Firepower Threat Defense
A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device.
local
low complexity
cisco CWE-78
4.6
2017-01-26 CVE-2017-3805 Information Exposure vulnerability in Cisco IOX 1.0(0)
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the device.
network
low complexity
cisco CWE-200
5.0
2017-01-26 CVE-2017-3804 Denial of Service vulnerability in Multiple Cisco Nexus Devices
A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of Cisco Nexus 5000, 6000, and 7000 Series Switches software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device.
5.7
2017-01-26 CVE-2017-3802 Cross-site Scripting vulnerability in Cisco Unified Communications Manager 12.0(0.99000.9)
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
cisco CWE-79
4.3
2017-01-26 CVE-2017-3800 Improper Input Validation vulnerability in Cisco Email Security Appliance 9.7.1066/9.7.1Hp2207/9.8.5085
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device.
network
low complexity
cisco CWE-20
5.0