Latest CVE Feed
-
4.3
MEDIUMCVE-2018-0218
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to i... Read more
Affected Products : secure_access_control_server_solution_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0217
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system. The vulnerability is due to in... Read more
Affected Products : asr_5500_firmware asr_5000_firmware asr_5700_firmware asr_5000 asr_5500 asr_5700- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2018-0216
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vu... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0215
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vu... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0214
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These com... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0213
A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could expl... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0212
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affecte... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-0211
A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be manually rebooted to recover. The vulnerability is due to ... Read more
Affected Products : identity_services_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0210
A vulnerability in the web-based management interface of Cisco Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulne... Read more
Affected Products : data_center_network_manager- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2018-0209
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a d... Read more
Affected Products : small_business_500_series_stackable_managed_switches_firmware sf500-24 sf500-24p sf500-48 sf500-48p sg500-28 sg500-28mpp sg500-28p sg500-52 sg500-52mp +10 more products- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0208
A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface ... Read more
Affected Products : email_encryption- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0207
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to i... Read more
Affected Products : secure_access_control_server_solution_engine- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0206
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of ... Read more
Affected Products : unified_communications_manager- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0205
A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to improper input validation. An attac... Read more
Affected Products : prime_collaboration_provisioning- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0204
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An at... Read more
Affected Products : prime_collaboration_provisioning- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0203
A vulnerability in the SMTP relay of Cisco Unity Connection could allow an unauthenticated, remote attacker to send unsolicited email messages, aka a Mail Relay Vulnerability. The vulnerability is due to improper handling of domain information in the affe... Read more
Affected Products : unity_connection- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0202
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms wh... Read more
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0201
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input during w... Read more
Affected Products : jabber- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0200
A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface of an affected product. The vulner... Read more
Affected Products : prime_service_catalog- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0199
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script in at... Read more
Affected Products : jabber- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024