Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-08-30 CVE-2019-1969 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic.
network
low complexity
cisco CWE-20
5.0
2019-08-30 CVE-2019-1968 Improper Encoding or Escaping of Output vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart.
network
low complexity
cisco CWE-116
5.0
2019-08-28 CVE-2019-1965 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Nx-Os
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination.
network
low complexity
cisco CWE-772
4.0
2019-08-28 CVE-2019-1963 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application on an affected device to restart unexpectedly.
network
low complexity
cisco CWE-20
6.8
2019-08-21 CVE-2019-1984 Improper Input Validation vulnerability in Cisco Enterprise Network Function Virtualization Infrastructure Sofware
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device.
network
low complexity
cisco CWE-20
5.5
2019-08-21 CVE-2019-1948 Improper Certificate Validation vulnerability in Cisco Webex Meetings 11.3/39.5
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate.
network
cisco CWE-295
4.3
2019-08-21 CVE-2019-1908 Unspecified vulnerability in Cisco products
A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information.
network
low complexity
cisco
5.0
2019-08-21 CVE-2019-1907 Unspecified vulnerability in Cisco products
A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges.
network
low complexity
cisco
6.5
2019-08-21 CVE-2019-12634 Permissions, Privileges, and Access Controls vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-264
5.0
2019-08-21 CVE-2019-12627 Improper Access Control vulnerability in Cisco Firepower Threat Defense
A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data.
network
low complexity
cisco CWE-284
5.0