Latest CVE Feed
-
6.5
MEDIUMCVE-2018-0267
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient prote... Read more
Affected Products : unified_communications_manager- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0266
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker c... Read more
Affected Products : unified_communications_manager- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-0264
A vulnerability in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow an unauthenticated, remote attacker to execute arbitrary code on the system of a targeted user. An attacker could exploit this vulnerability ... Read more
Affected Products : webex_meeting_server webex_meetings webex_business_suite_32 webex_business_suite_31- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2018-0263
A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, whic... Read more
Affected Products : meeting_server- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-0262
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect ... Read more
Affected Products : meeting_server- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0260
A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and download the contents of certain web application virtual directories. The vulnerability is due to lack of proper input validation and autho... Read more
Affected Products : mate_live- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0259
A vulnerability in the web-based management interface of Cisco MATE Collector could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is d... Read more
Affected Products : mate_collector- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0258
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affec... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0257
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnera... Read more
- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2018-0256
A vulnerability in the peer-to-peer message processing functionality of Cisco Packet Data Network Gateway could allow an unauthenticated, remote attacker to cause the Session Manager (SESSMGR) process on an affected device to restart, resulting in a denia... Read more
- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0255
A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due ... Read more
Affected Products : ios- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0254
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass configured file action policies if an Intelligent Application Bypass (IAB) with a drop percentage threshold is also config... Read more
- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0253
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted us... Read more
Affected Products : secure_access_control_system- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0252
A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in ... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0251
A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting ... Read more
Affected Products : adaptive_security_appliance_software- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
4.1
MEDIUMCVE-2018-0250
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect ac... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0249
A vulnerability when handling incoming 802.11 Association Requests for Cisco Aironet 1800 Series Access Point (APs) on Qualcomm Atheros (QCA) based hardware platforms could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) con... Read more
Affected Products : aironet_access_point_software- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0248
A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could allow an aUTHENTICated, remote attacker to cause the device to reload unexpectedly during device configuration when the administrator is ... Read more
Affected Products : wireless_lan_controller_software- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0247
A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulne... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0245
A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is due ... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024