Latest CVE Feed
-
7.5
HIGHCVE-2017-3841
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5).... Read more
Affected Products : secure_access_control_system- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3842
A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455... Read more
Affected Products : intrusion_prevention_system_device_manager- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3898
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP b... Read more
Affected Products : livesafe- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-3846
A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could allow an unauthenticated, remote attacker to retrieve any file from the Client Manager Server. The vulnerability is due to insufficient in... Read more
Affected Products : tidal_enterprise_scheduler- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3859
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format strin... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3871
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The ... Read more
Affected Products : prime_optical- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-3860
Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3854
A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote attacker to impersonate a WLC in a meshed topology. The vulnerability is due to insufficient authentication of the parent access point ... Read more
Affected Products : wireless_lan_controller_software wireless_lan_controller_firmware wireless_lan_controller_software 2500_wireless_lan_controller 5500_wireless_lan_controller 7500_wireless_lan_controller 2504_wireless_lan_controller 5508_wireless_lan_controller 7510_wireless_lan_controller 8510_wireless_lan_controller +3 more products- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3869
An API Credentials Management vulnerability in the APIs for Cisco Prime Infrastructure could allow an authenticated, remote attacker to access an API that should be restricted to a privileged user. The attacker needs to have valid credentials. More Inform... Read more
Affected Products : prime_infrastructure- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3880
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 ... Read more
Affected Products : webex_meetings_server- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-3864
A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs du... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3874
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2)... Read more
Affected Products : unified_communications_manager- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3877
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. ... Read more
Affected Products : unified_communications_manager- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-3883
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload... Read more
Affected Products : nx-os firepower_extensible_operating_system fxos mds_9000 nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nexus_5000 nexus_3000 +37 more products- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3902
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.... Read more
Affected Products : epolicy_orchestrator- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3894
A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3897
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execut... Read more
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3933
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3934
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-4012
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request.... Read more
Affected Products : network_data_loss_prevention- Published: May. 17, 2017
- Modified: Apr. 20, 2025