Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-05 CVE-2019-1734 Unspecified vulnerability in Cisco Firepower Extensible Operating System and Nx-Os
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted.
local
low complexity
cisco
5.5
2019-11-05 CVE-2019-15966 Improper Input Validation vulnerability in Cisco Telepresence Advanced Media Gateway 1.1
A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
6.8
2019-10-16 CVE-2019-15962 Incorrect Default Permissions vulnerability in Cisco Telepresence Collaboration Endpoint
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device.
local
low complexity
cisco CWE-276
6.6
2019-10-16 CVE-2019-15282 Missing Authentication for Critical Function vulnerability in Cisco Identity Services Engine Software
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device.
network
low complexity
cisco CWE-306
5.0
2019-10-16 CVE-2019-15273 Unspecified vulnerability in Cisco Telepresence Collaboration Endpoint
Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files.
local
low complexity
cisco
6.6
2019-10-16 CVE-2019-15264 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation of Cisco Aironet and Catalyst 9100 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-400
6.1
2019-10-16 CVE-2019-15258 NULL Pointer Dereference vulnerability in Cisco Spa112 Firmware and Spa122 Firmware
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device.
network
low complexity
cisco CWE-476
6.8
2019-10-16 CVE-2019-15257 Unspecified vulnerability in Cisco Spa112 Firmware and Spa122 Firmware
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco
4.0
2019-10-16 CVE-2019-15252 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Spa112 Firmware and Spa122 Firmware
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges.
low complexity
cisco CWE-119
5.2
2019-10-16 CVE-2019-15251 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Spa112 Firmware and Spa122 Firmware
Multiple vulnerabilities in Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, adjacent attacker to execute arbitrary code with elevated privileges.
low complexity
cisco CWE-119
5.2