Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-06-30 CVE-2015-4229 Information Exposure vulnerability in Cisco Unified Communications Domain Manager 8.1.4Er1
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.
network
low complexity
cisco CWE-200
5.0
2015-06-27 CVE-2015-4225 Permissions, Privileges, and Access Controls vulnerability in Cisco Nx-Os 1.0(1.110A)/1.0(1E)
Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
network
low complexity
cisco CWE-264
4.0
2015-06-26 CVE-2015-4222 SQL Injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1)
SQL injection vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq46325.
network
low complexity
cisco CWE-89
6.5
2015-06-26 CVE-2015-4221 Permissions, Privileges, and Access Controls vulnerability in Cisco Unified Communications Manager IM and Presence Service 9.1(1)
Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.
network
low complexity
cisco CWE-264
4.0
2015-06-26 CVE-2015-4217 Information Exposure vulnerability in Cisco products
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a private key from another installation, aka Bug IDs CSCus29681, CSCuu95676, and CSCuu96601.
network
cisco CWE-200
4.3
2015-06-26 CVE-2015-4216 Information Exposure vulnerability in Cisco products
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH root authorized key across different customers' installations, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of a private key from another installation, aka Bug IDs CSCuu95988, CSCuu95994, and CSCuu96630.
network
low complexity
cisco CWE-200
5.0
2015-06-25 CVE-2015-4223 Resource Management Errors vulnerability in Cisco IOS XR 5.1.3
Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.
network
low complexity
cisco CWE-399
5.0
2015-06-25 CVE-2015-4220 Cross-site Scripting vulnerability in Cisco Unified Presence Server 9.1(1)
Cross-site scripting (XSS) vulnerability in Cisco Unified Presence Server 9.1(1) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq03773.
network
cisco CWE-79
4.3
2015-06-24 CVE-2015-4219 Permissions, Privileges, and Access Controls vulnerability in Cisco products
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
network
low complexity
cisco CWE-264
4.0
2015-06-24 CVE-2015-4218 Information Exposure vulnerability in Cisco Jabber
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
network
low complexity
cisco CWE-200
5.0