Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-02-18 CVE-2015-0617 Resource Management Errors vulnerability in Cisco ASR 5000 Series Software
Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outage) via malformed SNMP packets, aka Bug ID CSCur13393.
network
low complexity
cisco CWE-399
5.0
2015-02-17 CVE-2014-8023 Permissions, Privileges, and Access Controls vulnerability in Cisco Adaptive Security Appliance Software
Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.
network
low complexity
cisco CWE-264
4.0
2015-02-12 CVE-2015-0611 Permissions, Privileges, and Access Controls vulnerability in Cisco Telepresence System Software IX 8.0.0/8.0.1
The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-recovery account's access, which allows remote authenticated users to obtain HelpDesk-equivalent privileges by leveraging device-recovery authentication, aka Bug ID CSCus74174.
network
low complexity
cisco CWE-264
6.5
2015-02-12 CVE-2015-0610 Race Condition vulnerability in Cisco IOS
Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.
network
cisco CWE-362
4.3
2015-02-12 CVE-2015-0606 Improper Input Validation vulnerability in Cisco IOS
The IOS Shell in Cisco IOS allows local users to cause a denial of service (device crash) via unspecified commands, aka Bug ID CSCur59696.
local
low complexity
cisco CWE-20
4.9
2015-02-12 CVE-2015-0580 SQL Injection vulnerability in Cisco Secure Access Control System
Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID CSCuq79027.
network
low complexity
cisco CWE-89
6.5
2015-02-12 CVE-2014-3365 Cross-site Scripting vulnerability in Cisco Prime Security Manager
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
network
cisco CWE-79
4.3
2015-02-12 CVE-2014-2153 Cross-site Scripting vulnerability in Cisco Prime Infrastructure
Multiple cross-site scripting (XSS) vulnerabilities in INSERT pages in Cisco Prime Infrastructure allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun21869.
network
cisco CWE-79
4.3
2015-02-12 CVE-2014-2152 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Prime Infrastructure
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.
network
cisco CWE-352
6.8
2015-02-12 CVE-2014-2147 Improper Input Validation vulnerability in Cisco Prime Infrastructure
The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444.
network
cisco CWE-20
4.3