Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-06 CVE-2020-3308 Improper Verification of Cryptographic Signature vulnerability in Cisco products
A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an affected device.
network
low complexity
cisco CWE-347
4.0
2020-05-06 CVE-2020-3307 Improper Input Validation vulnerability in Cisco Firepower Management Center
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device.
network
low complexity
cisco CWE-20
5.0
2020-05-06 CVE-2020-3285 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3 policy to block traffic for a specific URL.
network
low complexity
cisco
5.0
2020-05-06 CVE-2020-3283 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-787
5.0
2020-05-06 CVE-2020-3256 XXE vulnerability in Cisco Hosted Collaboration Mediation Fulfillment
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
4.0
2020-05-06 CVE-2020-3255 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
5.0
2020-05-06 CVE-2020-3246 Injection vulnerability in Cisco Umbrella
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service.
network
cisco CWE-74
4.3
2020-05-06 CVE-2020-3189 Memory Leak vulnerability in Cisco products
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unexpected system behaviors or device crashes.
network
low complexity
cisco CWE-401
5.0
2020-05-06 CVE-2020-3188 Insufficient Session Expiration vulnerability in Cisco products
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition.
network
low complexity
cisco CWE-613
5.0
2020-05-06 CVE-2020-3186 Unspecified vulnerability in Cisco products
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system.
network
low complexity
cisco
5.0