Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-15 CVE-2012-1326 Improper Input Validation vulnerability in Cisco Ironport web Security Appliance 7.5
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks
network
cisco CWE-20
5.8
2020-01-15 CVE-2012-1316 Improper Certificate Validation vulnerability in Cisco Ironport web Security Appliance
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
network
cisco CWE-295
4.3
2020-01-06 CVE-2019-15999 Unspecified vulnerability in Cisco Data Center Network Manager
A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device.
network
low complexity
cisco
4.0
2020-01-06 CVE-2019-15983 XXE vulnerability in Cisco Data Center Network Manager
A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system.
network
low complexity
cisco CWE-611
4.0
2019-11-26 CVE-2019-16002 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
cisco CWE-352
4.3
2019-11-26 CVE-2019-16001 Uncontrolled Search Path Element vulnerability in Cisco Webex Meetings and Webex Teams
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack.
local
cisco CWE-427
4.4
2019-11-26 CVE-2019-15998 Missing Authorization vulnerability in Cisco IOS XR 6.5.1/6.5.2/6.5.3
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device.
network
low complexity
cisco CWE-862
5.0
2019-11-26 CVE-2019-15995 SQL Injection vulnerability in Cisco DNA Spaces: Connector
A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries.
network
low complexity
cisco CWE-89
5.5
2019-11-26 CVE-2019-15994 Cross-site Scripting vulnerability in Cisco Stealthwatch Enterprise 6.10.2
A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system.
network
cisco CWE-79
4.3
2019-11-26 CVE-2019-15990 Unspecified vulnerability in Cisco products
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface.
network
low complexity
cisco
5.0