Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-23 CVE-2019-15993 Improper Authentication vulnerability in Cisco products
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information.
network
low complexity
cisco CWE-287
5.3
2020-09-23 CVE-2019-16000 Insufficient Verification of Data Authenticity vulnerability in Cisco Umbrella Roaming Client 2.2.238
A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applications on a targeted device.
local
low complexity
cisco CWE-345
4.4
2020-09-23 CVE-2019-16004 Missing Authentication for Critical Function vulnerability in Cisco Vision Dynamic Signage Director
A vulnerability in the REST API endpoint of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected device.
network
low complexity
cisco CWE-306
6.5
2020-09-23 CVE-2019-16017 Improper Input Validation vulnerability in Cisco Unified Customer Voice Portal
A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to execute Insecure Direct Object Reference actions on specific pages within the OAMP application.
network
low complexity
cisco CWE-20
6.8
2020-09-23 CVE-2019-16025 Cross-site Scripting vulnerability in Cisco Emergency Responder
A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
4.8
2020-09-23 CVE-2019-1983 Improper Input Validation vulnerability in Cisco Asyncos and Content Security Management Appliance
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to cause repeated crashes in some internal processes that are running on the affected devices, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2020-09-23 CVE-2019-15963 Unspecified vulnerability in Cisco Unified Communications Manager
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software.
network
low complexity
cisco
6.5
2020-09-23 CVE-2019-15974 Improper Input Validation vulnerability in Cisco Managed Services Accelerator
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco CWE-20
6.1
2020-09-23 CVE-2020-3137 Cross-site Scripting vulnerability in Cisco Email Security Appliance
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1
2020-09-23 CVE-2020-3130 Improper Input Validation vulnerability in Cisco Unity Connection
A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem.
network
low complexity
cisco CWE-20
6.5