Latest CVE Feed
-
7.5
HIGHCVE-2018-0090
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded ... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0089
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0088
A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow an authenticated, local attacker to impact the stability of the device. This could result in arbitrary code... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-0087
A vulnerability in the FTP server of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to log in to the FTP server of the device without a valid password. The attacker does need to have a valid username. The vulnerabil... Read more
- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0086
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVIT... Read more
Affected Products : unified_customer_voice_portal- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0063
A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing interfaces (IRIs) next-hop limit. Once the IRI next-hop database is full, no ... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0062
A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service which may prevent other users to authenticate or to perform J-Web operations. Affected releases are Juniper Networks Junos OS: 12.1X46 ve... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0061
A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect system performance. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81 on... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0060
An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of Service to the dcd process and interfaces and connected clients when the Junos device is requesting an IP... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0059
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a ... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0058
Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device to reboot. The issue is specific to the processing of Broadband Edge (BBE) client route processing on MX Series subscriber management p... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-0057
On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address bindi... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0056
If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the Layer 2 Address Learning Daemon (L2ALD) daemon might crash when attempting to ... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0055
Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband Edge (BBE) environment may result in a jdhcpd daemon crash. The daemon automatically restarts without intervention, but a continuous rec... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0054
On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can cause egress interface congestion, resulting in routing protocol packet drops, such as BGP, leading to peeri... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0053
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially booted up. Affected releases are J... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0052
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0051
A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allows an attacker to crash MS-PIC, MS-MIC, MS-MPC, MS-DPC or SRX flow daemon (flowd) process. This issue affects Junos OS devices with NAT ... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0050
An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cause RPD to crash. Continued receipt of this malformed MPLS RSVP packet will cause a sustained Denial of Service condition. Affected rele... Read more
Affected Products : junos- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0049
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of this specifically crafted malicious MPLS packet will cause a sustained Denial of Service condition. This i... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024