Latest CVE Feed
-
7.4
HIGHCVE-2018-0165
A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust buffers on an affected device, resulting in a denial of service (DoS) co... Read more
Affected Products : ios_xe catalyst_4000 catalyst_3850-12s-e catalyst_3850-12s-s catalyst_3850-12xs-e catalyst_3850-12xs-s catalyst_3850-16xs-e catalyst_3850-16xs-s catalyst_3850-24p-e catalyst_3850-24p-l +37 more products- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0164
A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker coul... Read more
Affected Products : ios_xe- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0163
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change ... Read more
Affected Products : ios 1921_integrated_services_router 1941_integrated_services_router 1941w_integrated_services_router 2901_integrated_services_router 2911_integrated_services_router 2921_integrated_services_router 2951_integrated_services_router 3925_integrated_services_router 3925e_integrated_services_router +86 more products- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2018-0160
A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of memory resources... Read more
Affected Products : ios_xe asr_901-12c-f-d asr_901-12c-ft-d asr_901-4c-f-d asr_901-4c-ft-d asr_901-6cz-f-a asr_901-6cz-f-d asr_901-6cz-fs-a asr_901-6cz-fs-d asr_901-6cz-ft-a +10 more products- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0157
A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker coul... Read more
Affected Products : ios_xe- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0152
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does not reset the pr... Read more
Affected Products : ios_xe- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0150
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credenti... Read more
- Published: Mar. 28, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-0149
A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored ... Read more
Affected Products : integrated_management_controller_supervisor- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0148
A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack... Read more
Affected Products : ucs_director- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2018-0146
A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by t... Read more
Affected Products : data_center_analytics_framework- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0145
A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an a... Read more
Affected Products : data_center_analytics_framework- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0144
A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affe... Read more
Affected Products : prime_data_center_network_manager- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2018-0141
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An at... Read more
Affected Products : prime_collaboration_provisioning prime_collaboration prime_collaboration_assurance- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0140
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information... Read more
Affected Products : email_security_appliance_firmware content_security_management_appliance email_security_appliance_c160 email_security_appliance_c170 email_security_appliance_c190 email_security_appliance_c370 email_security_appliance_c370d email_security_appliance_c380 email_security_appliance_c390 email_security_appliance_c670 +9 more products- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0139
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial ... Read more
Affected Products : unified_customer_voice_portal- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0138
A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulner... Read more
Affected Products : firepower_threat_defense- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0137
A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate limiting protection for ... Read more
Affected Products : prime_network- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0136
A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting... Read more
- Published: Jan. 31, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0135
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search i... Read more
Affected Products : unified_communications_manager- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0134
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component ... Read more
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024